What is CVE-2026-67347?
This critical vulnerability in Vendure e-commerce platform up to version 3.7.1 allows channel-scoped administrators to bypass cross-channel authorization and modify other tenants' data, such as stock locations and assets. The issue is fixed in commit f67ef5f, so immediate patching or restricting affected service methods is strongly recommended.
Azərbaycanca: Bu kritik zəiflik Vendure e-ticarət platformasının 3.7.1-ə qədər versiyalarında aşkarlanıb, burada cross-channel authorization bypass administratorlara aidiyyatı olmayan təşkilatların stok yerləri və aktivlərini dəyişməyə imkan verir. Təcili olaraq commit f67ef5f ilə yenilənməli, ya da təsirlənmiş 'stock-location.service.ts' və 'asset.service.ts' metodlarına məhdudlaşdırma tətbiq edilməlidir.
Related CVEs
link basis: same weakness class CWE-863
FAQ2
What versions of the Vendure platform are affected by CVE-2026-67347?
This critical vulnerability affects Vendure e-commerce platform versions up to 3.7.1.
Which commit is recommended for patching the vulnerability?
Immediate patching with commit f67ef5f is strongly recommended to fix the vulnerability.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.