What is CVE-2026-48744?
Saleor e-commerce platform has a broken authorization check in "saleor/permission/utils.py". This vulnerability allows anonymous callers to alter channel order using the "channelUpdate()" GraphQL mutation. Organizations running affected versions should immediately apply the security update.
Azərbaycanca: Saleor e-ticarət platformasında "saleor/permission/utils.py" faylında autentifikasiya yoxlamasının pozulması (broken authorization) mövcuddur. Bu zəiflik anonim istifadəçilərə "channelUpdate()" GraphQL mutasiyası vasitəsilə kanal sıralamasını dəyişməyə imkan verir. Platformanın müvafiq versiyalarını istifadə edən təşkilatlar dərhal təhlükəsizlik yeniləməsini tətbiq etməlidir.
Related CVEs
link basis: same weakness class CWE-284
FAQ2
What unauthorized operation does CVE-2026-48744 allow in the Saleor platform?
This vulnerability allows anonymous callers to alter channel order using the "channelUpdate()" GraphQL mutation.
In which component of Saleor is CVE-2026-48744 located?
The vulnerability is related to a broken authorization check in the "saleor/permission/utils.py" file.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.