What is CVE-2026-47127?
Ghostfolio open-source wealth management software grants Premium subscriptions via the `GET /api/v1/subscription/stripe/callback` endpoint without validating the Stripe Checkout Session ID. This affects versions prior to 3.4.0, allowing anyone to gain Premium access without payment. Upgrading to version 3.4.0 or later is recommended.
Azərbaycanca: Ghostfolio açıq mənbəli sərvət idarəetmə proqramında `GET /api/v1/subscription/stripe/callback` endpoint-i Stripe Checkout Session ID-sini yoxlamadan Premium abunəlik verir. Bu, 3.4.0 versiyasından əvvəlki versiyalara təsir edir və istənilən şəxsə ödəniş etmədən Premium giriş əldə etməyə imkan yaradır. Proqramı 3.4.0 və ya daha yeni versiyaya yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-862; shared vendor: Stripe
FAQ2
What does CVE-2026-47127 allow in Ghostfolio?
The vulnerability allows anyone to gain Premium access without payment, because the `GET /api/v1/subscription/stripe/callback` endpoint does not validate the Stripe Checkout Session ID.
Which Ghostfolio versions are affected by CVE-2026-47127 and how is it fixed?
It affects versions prior to 3.4.0, and the fix is upgrading to version 3.4.0 or later.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.