CVE-2026-44472: Saleor: Account pre-hijacking vulnerability due to unverified anonymous order merge

Published Aug 18, 2026
·
Updated

Saleor is an e-commerce platform. From 2.10.0rc1 until 3.21.67, 3.22.63, and 3.23.22, the account activation flow treats email verification as sufficient proof of account ownership and automatically associates anonymous commerce data with the newly activated account. An attacker can use accountRegister to create an account with a victim's email address before the victim registers. If the victim follows the activation link sent to that mailbox, Saleor activates the attacker-created account and saleor/graphql/account/mutations/account/confirmaccount.py can merge anonymous orders and gift-card data for the same email address without requiring the account password or another authentication factor. The attacker can then access the merged order history and personal data, including names, addresses, and phone numbers. The patched supported lines disable automatic merging by default, while the redesigned 3.24.0 flow requires password confirmation before anonymous objects are linked. This issue is fixed in versions 3.21.67, 3.22.63, and 3.23.22.

Affected Software

1 affected component
Saleor Saleor>2.10.0rc1<=3.21.67, >=2.10.0rc1<=3.22.63, >=2.10.0rc1<=3.23.22

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade Saleor to a version that resolves this vulnerability.

    Fixed in 3.21.67
  2. Upgrade

    Upgrade Saleor to a version that resolves this vulnerability.

    Fixed in 3.22.63
  3. Upgrade

    Upgrade Saleor to a version that resolves this vulnerability.

    Fixed in 3.23.22
  4. Configuration

    In Saleor versions where this issue is addressed but before upgrading, ensure the patched setting that disables automatic merging of anonymous commerce data by default is set to disabled, so activation via email verification does not automatically merge anonymous orders/gift-card data.

    Saleor automatic anonymous order merge (account activation flow) = disabled (default for patched supported lines)

Event History

Aug 18, 2026
CVE Published
via MITRE·05:11 PM
Data Sourced
via MITRE·05:11 PM
DescriptionSeverityWeakness

Frequently Asked Questions

1

Which versions address this issue?

Install 3.21.67, 3.22.63, or 3.23.22, depending on the supported release line in use. Version 3.24.0 also redesigns the flow to require password confirmation before anonymous objects are linked.

2

What conditions are required for exploitation?

An attacker only needs to register an account using the victim's email address before the victim does. Exploitation then depends on the victim activating that attacker-created account through the link delivered to their mailbox; the attacker does not need the victim's password or another authentication factor for the anonymous-data merge.

3

What information could be exposed?

The exposed data can include merged anonymous order history, gift-card data, and associated personal information such as names, addresses, and phone numbers. The attacker can access this information through the activated attacker-created account.

4

Are default configurations affected after upgrading?

In the patched supported release lines, automatic merging is disabled by default. The 3.24.0 flow instead requires password confirmation before linking anonymous objects.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203