Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2026-39851

20
FAUCET Score

BRIEFING NOTE: CVE-2026-39851 OVERVIEW CVE-2026-39851 is an information disclosure vulnerability affecting Saleor, a widely-used e-commerce platform. Versions 2.10.0 through 3.22.x and earlier 3.21.x releases contain a flaw in the requestEmailChange() mutation that inadvertently exposes the existence of user-provided email addresses through error messages. This affects all releases before versions 3.23.0a3, 3.22.47, 3.21.54, and 3.20.118, which have issued fixes for this issue. SEVERITY The vulnerability carries a CVSS 3.1 score of 4.3 (Medium) with a network-based attack vector requiring low complexity and valid user authentication. The attack has limited scope, affecting only the confidentiality of email address information with no impact to system integrity or availability. The FAUCET Risk Score of 38.0/100 indicates a relatively low overall risk profile compared to the broader vulnerability landscape. EXPLOITATION STATUS No evidence of active exploitation exists at this time. The vulnerability is not listed on CISA's Known Exploited Vulnerabilities (KEV) catalog, nor is it featured on active threat tracking lists. Community attention remains minimal based on available metrics, suggesting limited real-world exploitation attempts. Organizations should nonetheless prioritize patching affected Saleor instances as part of regular maintenance cycles.

Impacted Technologies

VendorProductVersion(s)CPE
>= 2.10.0, < 3.20.118CPE matchmatch criteria
cpe:2.3:a:saleor:saleor:*:*:*:*:*:*:*:*
>= 3.21.0, < 3.21.54CPE matchmatch criteria
cpe:2.3:a:saleor:saleor:*:*:*:*:*:*:*:*
>= 3.22.0, < 3.22.47CPE matchmatch criteria
cpe:2.3:a:saleor:saleor:*:*:*:*:*:*:*:*
3.23.0CPE matchmatch criteria
cpe:2.3:a:saleor:saleor:3.23.0:alpha0:*:*:*:*:*:*
3.23.0CPE matchmatch criteria
cpe:2.3:a:saleor:saleor:3.23.0:alpha1:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 4.0

5.3MEDIUM

CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

Attack Vector
NETWORK
Attack Complexity
LOW
Attack Requirements
NONE
Privileges Required
LOW
User Interaction
NONE
VS Confidentiality
LOW
VS Integrity
NONE
VS Availability
NONE
SS Confidentiality
NONE
SS Integrity
NONE
SS Availability
NONE
Exploit Maturity
NOT_DEFINED
CvssVersion
4.0

Exploit Intelligence

EPSS Score
0.24%
Probability of exploitation in next 30 days
EPSS Percentile
15.5%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.0024 is in the 18th percentile among its peer group of 21,974 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (1)

github_advisorypatch availablevia nvd_reference
View patch

References

github.com / saleor/saleor/commit/7be352fa8c35875d6e66d36493ca7c14c101bd64
Patch
github.com / saleor/saleor/commit/cdb66da97abb7c86939e384914cd8d9194f378e8
Patch
github.com / saleor/saleor/commit/d6a94e95bd77f3f733fa66afd1b1ac72e863ca2a
Patch
github.com / saleor/saleor/commit/e42aa4d6e588982e78942b033af051c8ec8f43fa
Patch
github.com / saleor/saleor/commit/f0371bdd4cafcc841f1a9e7049cead6133bf7464
Patch
github.com / saleor/saleor/security/advisories/GHSA-m3rm-m4vq-27x7
PatchVendor Advisory