CVE-2026-54608 | MythicalLTD MythicalDash up to 3.5.4-aurora Stripe Gateway Stripe.php User::addCreditsAtomic authorization
A vulnerability marked as problematic has been reported in MythicalLTD MythicalDash up to 3.5.4-aurora. This issue affects the function User::addCreditsAtomic of the file backend/app/Api/System/Gateways/Stripe.php of the component Stripe Gateway. This manipulation causes missing authorization.
This vulnerability is tracked as CVE-2026-54608. The attack is possible to be carried out remotely. No exploit exists.VulDB Recent EntriesRead More