CVE-2026-22589

HIGH

Spree < 4.10.2 - Unauthenticated Insecure Direct Object Reference

Title source: llm
STIX 2.1

Description

Spree is an open source e-commerce solution built with Ruby on Rails. Prior to versions 4.10.2, 5.0.7, 5.1.9, and 5.2.5, an Unauthenticated Insecure Direct Object Reference (IDOR) vulnerability was identified that allows an unauthenticated attacker to access guest address information without supplying valid credentials or session cookies. This issue has been patched in versions 4.10.2, 5.0.7, 5.1.9, and 5.2.5.

Scores

CVSS v3 7.5
EPSS 0.0038
EPSS Percentile 29.9%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation poc
Automatable yes
Technical Impact partial

Details

CWE
CWE-639
Status published
Products (2)
rubygems/spree_core 4.0.0 - 4.10.2RubyGems
spreecommerce/spree < 4.10.2
Published Jan 10, 2026
Tracked Since Feb 18, 2026