CVE-2026-44585
Received Received - Intake

Service ID Misreference in Paymenter Webshop

Vulnerability report for CVE-2026-44585, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-07-20

Last updated on: 2026-07-20

Assigner: GitHub, Inc.

Description

Paymenter is a free and open-source webshop solution for management of hosting services. In versions prior to 1.5.0, the ticket creation endpoint accepts a user-supplied service identifier without enforcing ownership validation, allowing authenticated users to create support tickets referencing services belonging to other accounts by modifying the service ID in the request. An attacker could modify the service ID value in the client-side request and successfully create a ticket associated with another user's service. The vulnerability requires authentication and does not provide direct access to service contents or customer data. However, referenced service information could become visible to support personnel handling the ticket. Successful exploitation could allow an authenticated user to: create support tickets referencing services belonging to other users, potentially cause support staff to interact with or review unrelated customer services. The vulnerability did not allow direct access to another user's service, modification of another user's service or retrieval of confidential service data through the vulnerable endpoint itself. This issue has been fixed in version 1.5.0.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-07-20
Last Modified
2026-07-20
Generated
2026-07-21
AI Q&A
2026-07-21
EPSS Evaluated
N/A
NVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
paymenter paymenter to 1.5.0 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-639 The system's authorization functionality does not prevent one user from gaining access to another user's data or record by modifying the key value identifying the data.
CWE-862 The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This is an authorization bypass vulnerability in Paymenter versions before 1.5.0. The ticket creation endpoint allows authenticated users to create support tickets for services they do not own by modifying the service ID in the request. This could lead to support staff reviewing unrelated customer services.

Detection Guidance

Check if your Paymenter instance is running a version prior to 1.5.0. Review server logs for unusual ticket creation activity where users reference services not belonging to them. Look for multiple ticket creation requests with modified service IDs.

Impact Analysis

An attacker could create support tickets for your services, potentially causing support staff to interact with or review your services. However, the attacker cannot directly access or modify your service data.

Compliance Impact

This vulnerability does not directly expose confidential data but could indirectly impact compliance by allowing unauthorized service references in support tickets. Support staff might review unrelated customer services, potentially violating data protection requirements like GDPR or HIPAA if sensitive service details are exposed during ticket handling.

Mitigation Strategies

Upgrade Paymenter to version 1.5.0 or later immediately. Ensure all authenticated users have valid service ownership checks enforced. Monitor support tickets for suspicious activity referencing unrelated services.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-44585. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart