Saleor is an e-commerce platform. From 2.10.0rc1 until 3.21.67, 3.22.63, and 3.23.22, the account activation flow treats email verification as sufficient proof of account ownership and automatically associates anonymous commerce data with the newly activated account. An attacker can use accountRegister to create an account with a victim's email address before the victim registers. If the victim follows the activation link sent to that mailbox, Saleor activates the attacker-created account and saleor/graphql/account/mutations/account/confirm_account.py can merge anonymous orders and gift-card data for the same email address without requiring the account password or another authentication factor. The attacker can then access the merged order history and personal data, including names, addresses, and phone numbers. The patched supported lines disable automatic merging by default, while the redesigned 3.24.0 flow requires password confirmation before anonymous objects are linked. This issue is fixed in versions 3.21.67, 3.22.63, and 3.23.22.
CVE-2026-44472
This high-severity CVE scores 8.1 under a secondary CVSS source (NVD's own analysis pending). EPSS exploit probability: 0.4%, top 63% of all CVEs by exploit prediction. GitHub Security Advisory data not yet ingested — confidence will rise once GHSA publishes (typical lag: hours to days for open-source ecosystem CVEs; never for infrastructure-only CVEs).
- High severity, but no confirmed exploitation yet
No vendor fix yet — apply a workaround or compensating control (WAF / firewall / segmentation) and watch for a patch.
- CVSS v3
- 8.1
- EG Score
- 8.1(medium)
- EG Risk
- 41(Track)EG Risk 41/100SSVC: Track
EG Risk is EchelonGraph's 0–100 priority score: it fuses intrinsic severity with real-world exploitation and automatability so you can rank equal-severity CVEs and fix the most dangerous first. Higher = act sooner. Distinct from the 0–10 EG Score (severity).
How it’s computedSeverity81% × 45%Exploitation0% × 40%Automatability30% × 15%Action: Routine — remediate on your standard cadence. - EPSS PROB
- 0%
- EPSS %ILE
- 37%
- KEV
- Not listed
Published
August 18, 2026
Last Modified
August 18, 2026
Advisory Details (8)
Auto-updated Aug 18, 20263.23.22
Patch available: saleor/saleor 3.23.22
https://github.com/saleor/saleor/releases/tag/3.23.223.22.63
Patch available: saleor/saleor 3.22.63
https://github.com/saleor/saleor/releases/tag/3.22.633.21.67
Patch available: saleor/saleor 3.21.67
https://github.com/saleor/saleor/releases/tag/3.21.67commit dc63e422afc9 (saleor/saleor)
Patch available: saleor/saleor 3.21.67 (contains commit dc63e422afc9)
https://github.com/saleor/saleor/commit/dc63e422afc9f6ce115d75f045886b01b4f13e2bcommit 5110542c1649 (saleor/saleor)
Fix landed in saleor/saleor commit 5110542c1649 — awaiting tagged release
https://github.com/saleor/saleor/commit/5110542c164991384fa3c4f01983e8c76823ce0fcommit 42516727823c (saleor/saleor)
Patch available: saleor/saleor 3.23.22 (contains commit 42516727823c)
https://github.com/saleor/saleor/commit/42516727823cb74cb6b875070956debecf9ffdb8commit 299cdfb1a573 (saleor/saleor)
Patch available: saleor/saleor 3.22.63 (contains commit 299cdfb1a573)
https://github.com/saleor/saleor/commit/299cdfb1a5737108b78b5c2c0d29b94f3b7331a2Account pre-hijacking vulnerability due to unverified anonymous order merge · Advisory · saleor/saleor · GitHub
https://github.com/saleor/saleor/security/advisories/GHSA-6whj-8p3f-2xqpWeakness Classification(1)
MITRE Common Weakness Enumeration — the root-cause categories this CVE belongs to.
Data Freshness Timeline
(refreshed 11× in last 7d / 22× in last 30d)
Each row is a source pipeline that fetched or updated this CVE on that date, with what changed. For example, "NVD update" means NVD published or revised its analysis for this CVE; "MITRE cvelistV5" means we ingested or refreshed it from the CNA feed. Most recent first.
- 2026-08-30 03:18 UTCEG score recompute
- 2026-08-30 01:22 UTCEPSS rescore
- 2026-08-29 03:48 UTCEG score recompute
- 2026-08-28 21:41 UTCEPSS rescore
- 2026-08-28 01:29 UTCEG score recompute
- 2026-08-27 14:25 UTCEPSS rescore
- 2026-08-27 02:03 UTCEG score recompute
- 2026-08-26 14:46 UTCEPSS rescore
- 2026-08-25 14:53 UTCEG score recompute
- 2026-08-25 13:49 UTCEPSS rescore
- 2026-08-24 15:28 UTCEG score recompute
- 2026-08-23 04:19 UTCEG score recompute
- 2026-08-23 00:19 UTCEPSS rescore
- 2026-08-22 04:53 UTCEG score recompute
- 2026-08-21 23:49 UTCEPSS rescore
- 2026-08-21 05:24 UTCEG score recompute
- 2026-08-20 22:55 UTCEPSS rescore
- 2026-08-19 18:15 UTCEG score recompute
- 2026-08-19 17:04 UTCEPSS rescore
- 2026-08-18 18:23 UTCEG score recompute
- 2026-08-18 17:26 UTCEG score recompute
- 2026-08-18 17:26 UTCMITRE cvelistV5first tracked
Related CVEs(same CWE)
Same CWE
10 shownCWE-287
Frequently asked(5)
What is CVE-2026-44472?
When was CVE-2026-44472 disclosed?
Is CVE-2026-44472 actively exploited?
What is the CVSS score of CVE-2026-44472?
How do I remediate CVE-2026-44472?
Dependency Blast Radius
Explore the affected products and dependency analysis for CVE-2026-44472
Is Your Infrastructure Affected by CVE-2026-44472?
EchelonGraph automatically scans your cloud infrastructure and maps CVE exposure using blast radius analysis.