Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2026-25758

24
FAUCET Score

CVE-2026-25758 is a critical Insecure Direct Object Reference (IDOR) vulnerability in Spree Commerce's guest checkout flow, affecting all versions prior to 4.10.3, 5.0.8, 5.1.10, 5.2.7, and 5.3.2. This flaw allows unauthenticated guest users to bind arbitrary guest addresses to their orders by manipulating address IDs, leading to unauthorized access to other guests' Personally Identifiable Information (PII) such as names, addresses, and phone numbers. With a CVSS score of 7.5 (HIGH), this vulnerability is easily exploitable over the network with low attack complexity and no user interaction, resulting in high confidentiality impact. There is no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or inclusion in the KEV catalog, though it has received some community discussion and media coverage.

Impacted Technologies

VendorProductVersion(s)CPE
< 4.10.3CPE matchmatch criteria
cpe:2.3:a:spreecommerce:spree:*:*:*:*:*:*:*:*
>= 5.0.0, < 5.0.8CPE matchmatch criteria
cpe:2.3:a:spreecommerce:spree:*:*:*:*:*:*:*:*
>= 5.1.0, < 5.1.10CPE matchmatch criteria
cpe:2.3:a:spreecommerce:spree:*:*:*:*:*:*:*:*
>= 5.2.0, < 5.2.7CPE matchmatch criteria
cpe:2.3:a:spreecommerce:spree:*:*:*:*:*:*:*:*
>= 5.3.0, < 5.3.2CPE matchmatch criteria
cpe:2.3:a:spreecommerce:spree:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 4.0

7.7HIGH

CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

Attack Vector
NETWORK
Attack Complexity
LOW
Attack Requirements
NONE
Privileges Required
NONE
User Interaction
NONE
VS Confidentiality
HIGH
VS Integrity
NONE
VS Availability
NONE
SS Confidentiality
NONE
SS Integrity
NONE
SS Availability
NONE
Exploit Maturity
PROOF_OF_CONCEPT
CvssVersion
4.0

Exploit Intelligence

EPSS Score
0.60%
Probability of exploitation in next 30 days
EPSS Percentile
45.2%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.0060 is in the 22nd percentile among its peer group of 51,551 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.

Media Mentions

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (6)

github_advisorypatch availablevia nvd_reference
View patch
rubygemspatch availablevia ghsa
Product: spree_apiFixed in: 4.10.3
rubygemspatch availablevia ghsa
Product: spree_apiFixed in: 5.0.8
rubygemspatch availablevia ghsa
Product: spree_apiFixed in: 5.1.10
rubygemspatch availablevia ghsa
Product: spree_apiFixed in: 5.2.7
rubygemspatch availablevia ghsa
Product: spree_apiFixed in: 5.3.2

Vendor Advisories (1)

rubygemsGHSA-87fh-rc96-6fr6high

Unauthenticated Spree Commerce users can access all guest addresses

Feb 5, 2026

References

github.com / spree/spree/blob/1341623f2ae92685cdbe232885bf5808fc8f9ca8/core/app/models/spree/order/address_book.rb
Patch
github.com / spree/spree/blob/1341623f2ae92685cdbe232885bf5808fc8f9ca8/core/app/models/spree/order/checkout.rb
Patch
github.com / spree/spree/blob/1341623f2ae92685cdbe232885bf5808fc8f9ca8/core/app/services/spree/checkout/update.rb
Patch
github.com / spree/spree/blob/1341623f2ae92685cdbe232885bf5808fc8f9ca8/core/lib/spree/permitted_attributes.rb
Patch
github.com / spree/spree/commit/15619618e43b367617ec8d2d4aafc5e54fa7b734
Patch
github.com / spree/spree/commit/29282d1565ba4f7bc2bbc47d550e2c0c6d0ae59f
Patch
github.com / spree/spree/commit/6650f96356faa0d16c05bcb516f1ffd5641741b8
Patch
github.com / spree/spree/commit/902d301ac83fd2047db1b9a3a99545162860f748
Patch
github.com / spree/spree/commit/ff7cfcfcfe0c40c60d03317e1d0ee361c6a6b054
Patch
github.com / spree/spree/security/advisories/GHSA-87fh-rc96-6fr6
ExploitVendor Advisory