CVE-2026-67347 | VendureHQ Vendure up to 3.7.1 Channel Isolation asset.service.ts update global IDs authorization

SecurityVulns

A vulnerability described as problematic has been identified in VendureHQ Vendure up to 3.7.1. The affected element is the function update of the file stock-location.service.ts/asset.service.ts of the component Channel Isolation. Such manipulation of the argument global IDs leads to authorization bypass.

This vulnerability is referenced as CVE-2026-67347. It is possible to launch the attack remotely. No exploit is available.

It is best practice to apply a patch to resolve this issue.VulDB Recent EntriesRead More