CVE-2026-54643 | CubeCart up to 6.7.4 Delete Note orders.index.inc.php order_id/delete-note privileges management

SecurityVulns

A vulnerability labeled as problematic has been found in CubeCart up to 6.7.4. This impacts an unknown function of the file admin/sources/orders.index.inc.php of the component Delete Note Handler. Executing a manipulation of the argument order_id/delete-note can lead to improper privilege management.

The identification of this vulnerability is CVE-2026-54643. The attack may be launched remotely. There is no exploit available.

The affected component should be upgraded.VulDB Recent EntriesRead More