SB2026020926 - Multiple vulnerabilities in spree_api
Published: February 9, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 2 secuirty vulnerabilities.
1) Improper access control (CVE-ID: CVE-2026-25758)
The vulnerability allows a remote attacker to gain unauthorized access to otherwise restricted functionality.
The vulnerability exists due to improper access restrictions in Spree Commerce's guest checkout flow. A remote user can gain access to other guests' personally identifiable information.
2) Authorization bypass through user-controlled key (CVE-ID: CVE-2026-25757)
The vulnerability allows a remote attacker to compromise the target system.
The vulnerability exists due to authorization bypass through user-controlled key. A remote attacker can view completed guest orders by Order ID.
Remediation
Install update from vendor's website.