LIVE · cybersecurity feed
Live wire
cve recordlow

CVE-2026-4549

Published
CVSS3.1
Severitylow
WeaknessCWE-285
ExploitedNot in CISA KEV

CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N

Description

A flaw has been found in mickasmt next-saas-stripe-starter 1.0.0. Affected by this issue is the function openCustomerPortal of the file actions/open-customer-portal.ts of the component Stripe API. This manipulation causes authorization bypass. Remote exploitation of the attack is possible. The complexity of an attack is rather high. The exploitation is known to be difficult.

References

← Back to the CVE Tracker

Our coverage of CVE-2026-4549

No stories yet. This page updates automatically when we publish reporting that references CVE-2026-4549.