SEPTEMBER 7, 2026
Live Feed
Back to database
Case File

CVE-2026-44585

MEDIUM · CVSS 5.4 EPSS 0.18% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-07-20 · Last synced 2026-08-19

CyberRota Analysis

AI-Generated

The ticket creation endpoint in Paymenter versions prior to 1.5.0 is vulnerable due to a lack of ownership validation, allowing authenticated users to create support tickets for services belonging to other accounts by altering the service ID in their requests. While this does not grant direct access to service data, it could expose service information to support personnel, potentially leading to confusion or mishandling of customer services. Organizations using affected versions should prioritize upgrading to 1.5.0 to mitigate this risk.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Detected Signals
exploit
GitHub PoC Links

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-44585
Severity
MEDIUM
CVSS
5.4
EPSS
0.18%

Original NVD Description

Paymenter is a free and open-source webshop solution for management of hosting services. In versions prior to 1.5.0, the ticket creation endpoint accepts a user-supplied service identifier without enforcing ownership validation, allowing authenticated users to create support tickets referencing services belonging to other accounts by modifying the service ID in the request. An attacker could modify the service ID value in the client-side request and successfully create a ticket associated with another user's service. The vulnerability requires authentication and does not provide direct access to service contents or customer data. However, referenced service information could become visible to support personnel handling the ticket. Successful exploitation could allow an authenticated user to: create support tickets referencing services belonging to other users, potentially cause support staff to interact with or review unrelated customer services. The vulnerability did not allow direct access to another user's service, modification of another user's service or retrieval of confidential service data through the vulnerable endpoint itself. This issue has been fixed in version 1.5.0.