Junglewise Threat Intelligence

CVE-2026-39851: Saleor user enumeration in requestEmailChange mutation

CVE-2026-39851 · Severity: medium · CVSS 4.3 · Published 2026-04-08

Technologies: Saleor. Vendors: Saleor.

Executive brief

Saleor is an e-commerce platform used to manage online storefronts. A security flaw in the email change process allowed the system to reveal whether specific email addresses were already registered in the database through descriptive error messages. An attacker could use this to identify valid customer accounts, potentially leading to targeted phishing attacks or further account compromise attempts.

Technical details

A user enumeration vulnerability exists in Saleor's GraphQL API due to an observable response discrepancy (CWE-204). The 'requestEmailChange()' mutation returns different error messages depending on whether a provided email address exists in the system. A remote attacker with low privileges (a registered account) can exploit this over the network to verify the existence of other users' email addresses. This information can be used for reconnaissance, spear-phishing, or building a target list of customers. The issue is resolved in versions 3.23.0a3, 3.22.47, 3.21.54, and 3.20.118 by standardizing error responses.

Affected products

  • Saleor Saleor >= 2.10.0, < 3.20.118; >= 3.21.0, < 3.21.54; >= 3.22.0, < 3.22.47; >= 3.23.0, < 3.23.0a3

Timeline

  • 2026-04-08: disclosed
  • 2026-04-08: advisory
  • 2026-04-08: patched

References

Related threats