Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2026-35407

25
FAUCET Score

OVERVIEW CVE-2026-35407 is an authorization bypass vulnerability affecting Saleor e-commerce platform versions 2.10.0 through 3.22.46, 3.21.53, and 3.20.117. The flaw exists in the email change confirmation workflow, which fails to validate that email-change tokens are bound to the authenticated user requesting the change. An attacker with valid credentials can replay an email-change token generated for another user's account to change that account's registered email address without authorization. SEVERITY The vulnerability carries a CVSS 3.1 score of 6.5 (Medium) with a network-based attack vector requiring low complexity and low privilege user access. While no confidentiality or availability impact is present, the integrity impact is rated high, as attackers can modify account email addresses. This could facilitate account takeover, password reset abuse, or denial of legitimate user access. The FAUCET risk score of 44.0 out of 100 reflects moderate concern within the threat landscape. EXPLOITATION STATUS There is currently no evidence of active exploitation in the wild, with the vulnerability remaining inactive on public known exploited vulnerability lists. The EPSS score of 0.00033 indicates minimal probability of exploitation relative to all disclosed vulnerabilities. However, organizations running affected Saleor versions should prioritize patching to versions 3.23.0a3, 3.22.47, 3.21.54, or 3.20.118 to close this authorization gap.

Impacted Technologies

VendorProductVersion(s)CPE
>= 2.10.0, < 3.20.118CPE matchmatch criteria
cpe:2.3:a:saleor:saleor:*:*:*:*:*:*:*:*
>= 3.20.119, < 3.21.54CPE matchmatch criteria
cpe:2.3:a:saleor:saleor:*:*:*:*:*:*:*:*
>= 3.22.0, < 3.22.47CPE matchmatch criteria
cpe:2.3:a:saleor:saleor:*:*:*:*:*:*:*:*
3.23.0CPE matchmatch criteria
cpe:2.3:a:saleor:saleor:3.23.0:*:*:*:*:*:*:*
3.23.0CPE matchmatch criteria
cpe:2.3:a:saleor:saleor:3.23.0:a0:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 4.0

5.9MEDIUM

CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:P/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

Attack Vector
NETWORK
Attack Complexity
HIGH
Attack Requirements
PRESENT
Privileges Required
LOW
User Interaction
PASSIVE
VS Confidentiality
NONE
VS Integrity
HIGH
VS Availability
NONE
SS Confidentiality
NONE
SS Integrity
NONE
SS Availability
NONE
Exploit Maturity
NOT_DEFINED
CvssVersion
4.0

Exploit Intelligence

EPSS Score
0.29%
Probability of exploitation in next 30 days
EPSS Percentile
21.5%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.0029 is in the 28th percentile among its peer group of 21,974 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (1)

github_advisorypatch availablevia nvd_reference
View patch

References

github.com / saleor/saleor/commit/7be352fa8c35875d6e66d36493ca7c14c101bd64
Patch
github.com / saleor/saleor/commit/cdb66da97abb7c86939e384914cd8d9194f378e8
Patch
github.com / saleor/saleor/commit/d6a94e95bd77f3f733fa66afd1b1ac72e863ca2a
Patch
github.com / saleor/saleor/commit/e42aa4d6e588982e78942b033af051c8ec8f43fa
Patch
github.com / saleor/saleor/commit/f0371bdd4cafcc841f1a9e7049cead6133bf7464
Patch
github.com / saleor/saleor/security/advisories/GHSA-hwph-9537-mc3p
Vendor Advisory