Description
Saleor is an e-commerce platform. Versions 3.2.0 through 3.20.109, 3.21.0-a.0 through 3.21.44 and 3.22.0-a.0 through 3.22.28 have a n Insecure Direct Object Reference (IDOR) vulnerability that allows unauthenticated actors to extract sensitive information in plain text. Orders created before Saleor 3.2.0 could have PIIs exfiltrated. The issue has been patched in Saleor versions: 3.22.29, 3.21.45, and 3.20.110. To workaround, temporarily block non-staff users from fetching order information (the order() GraphQL query) using a WAF.
INFO
Published Date :
2026-01-23T23:38:31.414Z
Last Modified :
2026-01-26T17:10:16.445Z
Source :
GitHub_M
AFFECTED PRODUCTS
The following products are affected by CVE-2026-24136 vulnerability.
| Vendors | Products |
|---|---|
| Saleor |
|
REFERENCES
Here, you will find a curated list of external links that provide in-depth information to CVE-2026-24136.