Junglewise Threat Intelligence

CVE-2026-35407: Saleor authorization bypass in email change workflow

CVE-2026-35407 · Severity: medium · CVSS 6.5 · Published 2026-04-08

Technologies: Saleor. Vendors: Saleor.

Executive brief

Saleor is an e-commerce platform used to manage online storefronts. A security flaw in the account management system allows an attacker to change another user's email address by reusing a security token intended for a different account. This could allow an attacker to take permanent control of a victim's account by redirecting password reset emails to an address they control.

Technical details

A business-logic and authorization vulnerability exists in Saleor's account email change workflow due to improper validation of confirmation tokens. The system fails to verify that an email change confirmation token was issued specifically for the currently authenticated user. An attacker with low privileges (a standard account) can generate a token for their own account and then replay that token while authenticated as a different user. This results in the second account's email address being updated to the attacker-specified address. This flaw can be leveraged for account takeover by utilizing subsequent password reset flows. The issue is fixed in versions 3.23.0a3, 3.22.47, 3.21.54, and 3.20.118.

Affected products

  • Saleor Saleor >= 2.10.0, < 3.20.118; >= 3.21.0, < 3.21.54; >= 3.22.0, < 3.22.47; >= 3.23.0, < 3.23.0a3

Timeline

  • 2026-04-08: disclosed
  • 2026-04-08: advisory
  • 2026-04-08: patched

References

Related threats