OVERVIEW CVE-2026-35407 is an authorization bypass vulnerability affecting Saleor e-commerce platform versions 2.10.0 through 3.22.46, 3.21.53, and 3.20.117. The flaw exists in the email change confirmation workflow, which fails to validate that email-change tokens are bound to the authenticated user requesting the change. An attacker with valid credentials can replay an email-change token generated for another user's account to change that account's registered email address without authorization. SEVERITY The vulnerability carries a CVSS 3.1 score of 6.5 (Medium) with a network-based attack vector requiring low complexity and low privilege user access. While no confidentiality or availability impact is present, the integrity impact is rated high, as attackers can modify account email addresses. This could facilitate account takeover, password reset abuse, or denial of legitimate user access. The FAUCET risk score of 44.0 out of 100 reflects moderate concern within the threat landscape. EXPLOITATION STATUS There is currently no evidence of active exploitation in the wild, with the vulnerability remaining inactive on public known exploited vulnerability lists. The EPSS score of 0.00033 indicates minimal probability of exploitation relative to all disclosed vulnerabilities. However, organizations running affected Saleor versions should prioritize patching to versions 3.23.0a3, 3.22.47, 3.21.54, or 3.20.118 to close this authorization gap.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 2.10.0, < 3.20.118CPE matchmatch criteria | cpe:2.3:a:saleor:saleor:*:*:*:*:*:*:*:* | ||
>= 3.20.119, < 3.21.54CPE matchmatch criteria | cpe:2.3:a:saleor:saleor:*:*:*:*:*:*:*:* | ||
>= 3.22.0, < 3.22.47CPE matchmatch criteria | cpe:2.3:a:saleor:saleor:*:*:*:*:*:*:*:* | ||
3.23.0CPE matchmatch criteria | cpe:2.3:a:saleor:saleor:3.23.0:*:*:*:*:*:*:* | ||
3.23.0CPE matchmatch criteria | cpe:2.3:a:saleor:saleor:3.23.0:a0:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:P/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.