CVE-2026-44584
Received Received - Intake

Email Verification Bypass in Paymenter Webshop

Vulnerability report for CVE-2026-44584, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-07-20

Last updated on: 2026-07-20

Assigner: GitHub, Inc.

Description

Paymenter is a free and open-source webshop solution for management of hosting services. In versions prior to 1.5.0, the email update functionality fails to invalidate the existing verification state when a user changes their email address, allowing a verified account to retain its verified status after switching to an unverified or unowned email address. When a user updated their email address, the system did not reset or revalidate the associated email verification status. As a result, the verification column remained set to β€œtrue” even after the email address was changed. Exploitation could potentially result in: misrepresentation of email ownership, bypass of verification-based trust assumptions, and abuse of features gated behind verified status. No direct unauthorized access to other users accounts or data is possible through this issue alone. This issue has been fixed in version 1.5.0.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-07-20
Last Modified
2026-07-20
Generated
2026-07-21
AI Q&A
2026-07-21
EPSS Evaluated
N/A
NVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
paymenter paymenter to 1.5.0 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-345 The product does not sufficiently verify the origin or authenticity of data, in a way that causes it to accept invalid data.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability affects Paymenter, a webshop solution for hosting services. In versions before 1.5.0, changing an email address does not invalidate the existing verification status. This means a verified account remains verified even if the email is changed to an unverified or unowned address.

Detection Guidance

To detect this vulnerability, check if the email verification status remains 'true' after a user updates their email address. Review database records for users with unverified or unowned email addresses but still marked as verified. Look for inconsistencies in the verification column after email changes.

Impact Analysis

This flaw could allow misrepresentation of email ownership, bypass verification-based trust features, and enable abuse of features restricted to verified users. However, it does not directly grant unauthorized access to other accounts or data.

Compliance Impact

This vulnerability could potentially impact compliance with GDPR and HIPAA by allowing unverified or incorrect email addresses to retain verified status. This may lead to misrepresentation of user identity, which could violate data accuracy and integrity requirements under GDPR Article 5 and HIPAA's integrity principles.

Mitigation Strategies

Upgrade to Paymenter version 1.5.0 or later. If upgrading is not immediately possible, manually verify and reset the email verification status for all users who have changed their email addresses. Ensure the system properly invalidates verification status during email updates.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-44584. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart