CVE-2026-25758 | Spree up to 4.10.2/5.0.7/5.1.9/5.2.6/5.3.1 address ID authorization (GHSA-87fh-rc96-6fr6 / EUVD-2026-5563)
A vulnerability, which was classified as problematic, has been found in Spree up to 4.10.2/5.0.7/5.1.9/5.2.6/5.3.1. Affected by this issue is some unknown functionality. The manipulation of the argument address ID leads to authorization bypass.
This vulnerability is uniquely identified as CVE-2026-25758. The attack is possible to be carried out remotely. No exploit exists.
It is advisable to upgrade the affected component.