What is CVE-2026-72536?
CVE-2026-72536 is a missing authentication vulnerability in Chaskiq up to commit 46dfdd1, allowing unauthenticated remote attackers to manipulate any tenant's Stripe subscription via the stripeCreateIntent GraphQL mutation due to lack of authentication and authorization checks. Users should update to the latest patched version immediately.
Azərbaycanca: CVE-2026-72536, Chaskiq platformasının 46dfdd1 commit-dək versiyalarında aşkarlanmış autentifikasiya boşluğudur. Bu boşluq uzaqdan autentifikasiya olunmamış hücumçulara stripeCreateIntent GraphQL mutasiyası vasitəsilə istənilən tenant-ın Stripe abunəliyini manipulyasiya etməyə imkan verir. Təhlükəsizlik üçün sistemi ən son versiyaya yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-306; shared vendor: Chaskiq
FAQ2
Which component does CVE-2026-72536 target in the Chaskiq platform?
The vulnerability targets the stripeCreateIntent GraphQL mutation, allowing unauthenticated attackers to manipulate any tenant's Stripe subscription.
What measure should be taken to protect against CVE-2026-72536?
Users should update to the latest patched version after commit 46dfdd1.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.