This release includes 2 security fixes for security teams reviewing exposed deployments.
Published 1d
Productivity & Wikis
✓ No known CVEs patched
This release patches 2 known CVEs
Topics
cart
checkout
commerce
composable
e-commerce
ecommerce
+12 more
graphql
headless
headless-commerce
multichannel
oms
order-management
payments
pim
python
shop
shopping-cart
store
Affected surfaces
auth
rbac
Summary
AI summaryFixed critical account hijacking vulnerabilities CVE-2026-44472 and CVE-2026-48744.
Full changelog
What's Changed
Changes:
- Fixed CVE-2026-44472 - Account pre-hijacking vulnerability due to unverified anonymous order merge by @NyanKiyoshi in https://github.com/saleor/saleor/commit/dc63e422afc9f6ce115d75f045886b01b4f13e2b
- Fixed CVE-2026-48744 - Anonymous users can bypass authorization checks in selected GraphQL paths by @NyanKiyoshi in https://github.com/saleor/saleor/commit/11efb4e9ea76942cf142bc01de8846cbaf764465
- tests: add missing test for old_id when fetching orders by @NyanKiyoshi in https://github.com/saleor/saleor/pull/19538
Thanks to @0xSmiley and @pavelkohout396 for reporting the issues!
[!NOTE]
Make sure to follow our upgrade guide if you use theconfirmAccount()mutation (CVE-2026-44472).
Full Changelog: https://github.com/saleor/saleor/compare/3.21.66...3.21.67
Security Fixes
- CVE-2026-44472 — Account pre-hijacking vulnerability due to unverified anonymous order merge
- CVE-2026-48744 — Anonymous users can bypass authorization checks in selected GraphQL paths
Weekly OSS security release digest.
The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.
No spam, unsubscribe anytime.
Share this release
Beta — feedback welcome: [email protected]