CVE-2026-55795 | CraftCMS Commerce up to 4.11.1/5.6.4 RateLimiter CartController.php actionUpdateCart number improper authentication
A vulnerability classified as critical was found in CraftCMS Commerce up to 4.11.1/5.6.4. This affects the function actionUpdateCart of the file src/controllers/CartController.php of the component RateLimiter. Such manipulation of the argument number leads to improper authentication.
This vulnerability is uniquely identified as CVE-2026-55795. The attack can be launched remotely. No exploit exists.
Upgrading the affected component is advised.VulDB Recent EntriesRead More