Junglewise Threat Intelligence

CVE-2026-32270: Craft CMS Craft Commerce information disclosure in PaymentsController

CVE-2026-32270 · Severity: medium · CVSS 4 · Published 2026-04-13

Vendors: Craft CMS.

Executive brief

Craft Commerce, an e-commerce platform for Craft CMS, contains a vulnerability that can leak customer information. If an attacker knows or guesses an order number, they can trigger an error during the payment process that reveals sensitive details like the customer's email address and physical shipping or billing addresses. This could lead to unauthorized access to private customer data and potential privacy concerns.

Technical details

An information disclosure vulnerability exists in the `PaymentsController::actionPay` component of Craft Commerce. The application retrieves order details by order number before fully validating the requester's authorization (specifically the matching email check for anonymous payments). When the authorization check fails, the resulting JSON error response incorrectly includes a serialized order object. This object contains sensitive fields including customer email, shipping address, and billing address. An unauthenticated attacker with knowledge of a valid order number can exploit this to retrieve private order data. The issue is fixed in versions 4.11.0 and 5.6.0.

Affected products

  • Craft CMS Commerce >= 4.0.0, <= 4.10.2
  • Craft CMS Commerce >= 5.0.0, <= 5.5.4

Timeline

  • 2026-04-13: patched: Versions 4.11.0 and 5.6.0 released
  • 2026-04-14: advisory: GitHub Advisory published

References