What is CVE-2026-72535?
A missing authentication vulnerability in Chaskiq up to commit 46dfdd1 allows unauthenticated remote attackers to mint Stripe Billing Portal sessions for any tenant via the stripeCustomerPortal GraphQL mutation. The mutation lacks authentication or authorization checks, enabling unauthorized access to billing portals. It is recommended to update Chaskiq to the latest version to address this issue.
Azərbaycanca: Chaskiq platformasında (46dfdd1 commit-inə qədər) aşkar edilmiş autentifikasiya çatışmazlığı zəifliyi uzaqdan autentifikasiya olunmamış hücumçulara stripeCustomerPortal GraphQL mutasiyası vasitəsilə istənilən tenant üçün Stripe Billing Portal sessiyaları yaratmağa imkan verir. Bu, hücumçulara hesablaşma portalına icazəsiz giriş əldə etməyə şərait yaradır. Bu problemdən qorunmaq üçün Chaskiq proqramını son versiyaya yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-306; shared vendor: Chaskiq
FAQ2
Which function in Chaskiq allows unauthenticated access?
The vulnerability lies in the stripeCustomerPortal GraphQL mutation, as it lacks authentication or authorization checks.
What can an attacker gain by exploiting CVE-2026-72535?
An unauthenticated remote attacker can mint Stripe Billing Portal sessions for any tenant and gain unauthorized access to billing portals.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.