top of page
perceptive_background_267k.jpg

Spree is an open source e-commerce solution built with Ruby on Rails. Prior to versions 4.10.2, 5.0.7, 5.1.9, and 5.2.5, an Unauthenticated Insecure Direct Obje…

Published:

9 januari 2026 om 23:00:00

Alert date:

10 januari 2026 om 13:10:58

Source:

nvd.nist.gov

Click to open the original link from this advisory

CVE-2026-22589 is an Unauthenticated Insecure Direct Object Reference (IDOR) vulnerability in Spree, an open source e-commerce solution built with Ruby on Rails. The vulnerability allows unauthenticated attackers to access guest address information without valid credentials or session cookies. Multiple versions are affected including versions prior to 4.10.2, 5.0.7, 5.1.9, and 5.2.5. The issue has been patched in the specified versions. This represents a significant privacy breach risk for e-commerce platforms using vulnerable Spree versions.

Technical details

Mitigation steps:

Affected products:

Spree Commerce

Related links:

Related CVE's:

Related threat actors:

IOC's:

This article was created with the assistance of AI technology by Perceptive.

© 2025 by Perceptive Security. All rights reserved.

email: info@perceptivesecurity.com

Deze website toont informatie afkomstig van externe bronnen; Perceptive aanvaardt geen verantwoordelijkheid voor de juistheid, volledigheid of actualiteit van deze informatie.

bottom of page