CVE-2026-19127: Insufficient verification of lifetime-deal redemption codes allows forgery of permanent paid subscriptions
An issue in the billing and license activation subsystem allows remote attackers to bypass payment authorization workflows. By exploiting insufficient cryptographic validation or lack of server-side state verification on promotional/lifetime-deal (LTD) redemption codes, an unauthenticated attacker can forge valid redemption tokens or replay existing single-use codes to activate permanent, tier-highest paid subscriptions without a financial transaction.
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in v2.21.10
Event History
Frequently Asked Questions
What is the severity of CVE-2026-19127?
CVE-2026-19127 has a severity rating of medium, with a score of 6.5.
What are the implications of CVE-2026-19127?
CVE-2026-19127 allows attackers to forge permanent paid subscriptions by exploiting insufficient verification of redemption codes.
How do I fix CVE-2026-19127?
To fix CVE-2026-19127, ensure that proper cryptographic validation and server-side state verification are implemented for redemption codes.
Who is affected by CVE-2026-19127?
Businesses and applications utilizing a billing and license activation subsystem that does not verify promotional or lifetime-deal redemption codes are affected by CVE-2026-19127.
What type of attack is associated with CVE-2026-19127?
CVE-2026-19127 is associated with remote attacks that exploit insufficient authorization workflows in payment processing.