Junglewise Threat Intelligence

CVE-2026-46408: Vvveb CMS authorization bypass in checkout endpoint

CVE-2026-46408 · Severity: high · CVSS 7.6 · Published 2026-05-15

Technologies: Givanz Vvveb CMS. Vendors: Givanz.

Executive brief

Vvveb CMS, a platform used for building websites and e-commerce stores, contains a security flaw in its checkout process. An attacker logged into the system can access and use another customer's shopping cart by simply changing a numerical ID in the web address. This allows unauthorized users to interfere with the order process, potentially leading to incorrect order fulfillment or the exposure of another customer's intended purchases.

Technical details

An Insecure Direct Object Reference (IDOR) vulnerability exists in Vvveb CMS prior to version 1.0.8.3 due to a lack of ownership verification in the checkout endpoint. The application loads cart data based on a user-supplied 'cart_id' parameter without verifying if the cart belongs to the authenticated session. An attacker with a valid account can provide a predictable cart identifier to load another user's cart into their own checkout flow. This allows the attacker to proceed through the payment and order creation process using the victim's cart contents. The vulnerability is classified as CWE-639 (Authorization Bypass Through User-Controlled Key) and is resolved in version 1.0.8.3.

Affected products

  • givanz Vvveb CMS < 1.0.8.3

Timeline

  • 2026-05-13: advisory: GitHub Security Advisory published by vendor
  • 2026-05-15: disclosed: CVE published to NVD

References

Related threats