CVE-2026-19127
Received Received - Intake

Billing Bypass via Forged License Tokens

Vulnerability report for CVE-2026-19127, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-06

Last updated on: 2026-08-06

Assigner: 4cdc9741-f887-419a-a2fd-acbbd2729276

Description

An issue in the billing and license activation subsystem allows remote attackers to bypass payment authorization workflows. By exploiting insufficient cryptographic validation or lack of server-side state verification on promotional/lifetime-deal (LTD) redemption codes, an unauthenticated attacker can forge valid redemption tokens or replay existing single-use codes to activate permanent, tier-highest paid subscriptions without a financial transaction.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-06
Last Modified
2026-08-06
Generated
2026-08-07
AI Q&A
2026-08-07
EPSS Evaluated
N/A
NVD

Affected Vendors & Products

Currently, no data is known.

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-345 The product does not sufficiently verify the origin or authenticity of data, in a way that causes it to accept invalid data.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is in the billing and license activation system. It allows remote attackers to bypass payment requirements by exploiting weak cryptographic validation or lack of server-side checks on promotional codes. Attackers can forge valid tokens or replay single-use codes to activate high-tier paid subscriptions without making a payment.

Impact Analysis

If you are a user of the affected software, an attacker could exploit this to obtain premium features without paying. This could lead to financial losses for the software vendor and potentially disrupt service availability or integrity for legitimate users.

Compliance Impact

This vulnerability could lead to unauthorized access to paid services without financial transactions, potentially violating data protection and privacy requirements under standards like GDPR and HIPAA. Unauthorized subscription activation may expose user data or enable misuse of services, which could result in non-compliance with regulatory obligations regarding data integrity and access controls.

Mitigation Strategies

Implement server-side state verification for redemption codes to prevent replay attacks. Ensure cryptographic validation is enforced for all promotional or lifetime-deal tokens. Require authentication for code redemption and log all activation attempts for monitoring.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-19127. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart