CVE-2026-39851

MEDIUM

Saleor has a user enumeration vulnerability due to different error messages

Title source: cna

Description

Saleor is an e-commerce platform. From 2.10.0 to before 3.23.0a3, 3.22.47, 3.21.54, and 3.20.118, the requestEmailChange() mutation was revealing the existence of user-provided email addresses in error messages. This vulnerability is fixed in 3.23.0a3, 3.22.47, 3.21.54, and 3.20.118.

Scores

CVSS v3 4.3
EPSS 0.0004
EPSS Percentile 10.7%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N

Details

CWE
CWE-204
Status published
Products (6)
saleor/saleor 3.23.0 alpha0 (3 CPE variants)
saleor/saleor 2.10.0 - 3.20.118
saleor/saleor >= 2.10.0, < 3.20.118
saleor/saleor >= 3.21.0-a.0, < 3.21.54
saleor/saleor >= 3.22.0-a.0, < 3.22.47
saleor/saleor >= 3.23.0-a.0, < 3.23.0a3
Published Apr 08, 2026
Tracked Since Apr 09, 2026