CVE-2026-4549 identifies an authorization bypass vulnerability in mickasmt next-saas-stripe-starter version 1.0.0, specifically affecting the openCustomerPortal function within its Stripe API component. This flaw allows for remote exploitation, but the attack complexity is high, making successful exploitation difficult. The potential impact is limited to low confidentiality due to the authorization bypass. There is currently no evidence of active exploitation, no public exploit code is available, and community discussion or media coverage is minimal.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| Mickasmt | Next-Saas-Stripe-Starter | 1.0.0CNA affected |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:H/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.