CVE-2026-54608 | MythicalLTD MythicalDash up to 3.5.4-aurora Stripe Gateway Stripe.php User::addCreditsAtomic authorization

SecurityVulns

A vulnerability marked as problematic has been reported in MythicalLTD MythicalDash up to 3.5.4-aurora. This issue affects the function User::addCreditsAtomic of the file backend/app/Api/System/Gateways/Stripe.php of the component Stripe Gateway. This manipulation causes missing authorization.

This vulnerability is tracked as CVE-2026-54608. The attack is possible to be carried out remotely. No exploit exists.VulDB Recent EntriesRead More