AUGUST 16, 2026
Live Feed
Back to database
Case File

CVE-2026-72535

HIGH · CVSS 8.6 EPSS 0.42% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-08-11 · Last synced 2026-08-16

CyberRota Analysis

AI-Generated

A missing authentication vulnerability in Chaskiq allows unauthenticated remote attackers to exploit the stripeCustomerPortal GraphQL mutation, enabling them to create Stripe Billing Portal sessions for any tenant. This flaw permits unauthorized access to and management of subscription data across multiple tenants, posing a significant risk to sensitive financial information. Organizations using Chaskiq should prioritize patching this vulnerability to protect against potential data breaches and unauthorized financial transactions.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

GitHub PoC Links

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-72535
Severity
HIGH
CVSS
8.6
EPSS
0.42%

Original NVD Description

A missing authentication vulnerability in Chaskiq through commit 46dfdd1 allows unauthenticated remote attackers to mint Stripe Billing Portal sessions for any tenant via the stripeCustomerPortal GraphQL mutation. The mutation performs no authentication or authorization checks before creating a customer portal session linked to any tenant Stripe account. An attacker can access and manage subscription data for any tenant without credentials.