BRIEFING NOTE: CVE-2026-39851 OVERVIEW CVE-2026-39851 is an information disclosure vulnerability affecting Saleor, a widely-used e-commerce platform. Versions 2.10.0 through 3.22.x and earlier 3.21.x releases contain a flaw in the requestEmailChange() mutation that inadvertently exposes the existence of user-provided email addresses through error messages. This affects all releases before versions 3.23.0a3, 3.22.47, 3.21.54, and 3.20.118, which have issued fixes for this issue. SEVERITY The vulnerability carries a CVSS 3.1 score of 4.3 (Medium) with a network-based attack vector requiring low complexity and valid user authentication. The attack has limited scope, affecting only the confidentiality of email address information with no impact to system integrity or availability. The FAUCET Risk Score of 38.0/100 indicates a relatively low overall risk profile compared to the broader vulnerability landscape. EXPLOITATION STATUS No evidence of active exploitation exists at this time. The vulnerability is not listed on CISA's Known Exploited Vulnerabilities (KEV) catalog, nor is it featured on active threat tracking lists. Community attention remains minimal based on available metrics, suggesting limited real-world exploitation attempts. Organizations should nonetheless prioritize patching affected Saleor instances as part of regular maintenance cycles.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 2.10.0, < 3.20.118CPE matchmatch criteria | cpe:2.3:a:saleor:saleor:*:*:*:*:*:*:*:* | ||
>= 3.21.0, < 3.21.54CPE matchmatch criteria | cpe:2.3:a:saleor:saleor:*:*:*:*:*:*:*:* | ||
>= 3.22.0, < 3.22.47CPE matchmatch criteria | cpe:2.3:a:saleor:saleor:*:*:*:*:*:*:*:* | ||
3.23.0CPE matchmatch criteria | cpe:2.3:a:saleor:saleor:3.23.0:alpha0:*:*:*:*:*:* | ||
3.23.0CPE matchmatch criteria | cpe:2.3:a:saleor:saleor:3.23.0:alpha1:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.