๐Ÿ” CVE Alert

CVE-2026-54643

MEDIUM 5.4

CubeCart: Missing Authorization Check for Order Note Deletion in orders.index.inc.php

CVSS Score
5.4
EPSS Score
0.0%
EPSS Percentile
0th

CubeCart is an ecommerce software solution. Prior to 6.7.5, the delete-note handler in admin/sources/orders.index.inc.php verifies only the presence of order_id and delete-note parameters before deleting records from CubeCart_order_notes, without requiring CC_PERM_DELETE for orders. An authenticated administrator lacking order modification privileges can directly invoke the handler with valid identifiers and delete order-history notes, removing operational records and audit-trail data. This issue is fixed in version 6.7.5.

CWE CWE-862
Vendor cubecart
Product v6
Published Sep 17, 2026
Stay Ahead of the Next One

Get instant alerts for cubecart v6

Be the first to know when new medium vulnerabilities affecting cubecart v6 are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L
Attack Vector
Network
Attack Complexity
Low
Privileges Required
Low
User Interaction
None
Scope
Unchanged
Confidentiality
None
Integrity
Low
Availability
Low

Affected Versions

cubecart / v6
< 6.7.5

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/cubecart/v6/security/advisories/GHSA-8mmq-8hpq-2h23 github.com: https://github.com/cubecart/v6/commit/2c1a3fc31a8d4aecbc8c4aa02ed878aac4d71879 github.com: https://github.com/cubecart/v6/blob/6.7.5/admin/sources/release_notes/6.7.5.inc.php github.com: https://github.com/cubecart/v6/releases/tag/6.7.5