HIGHVulnerability

CVE-2026-72535

A missing authentication vulnerability in Chaskiq through commit 46dfdd1 allows unauthenticated remote attackers to mint Stripe Billing Portal sessions for any tenant via the stripeCustomerPortal GraphQL mutation. The mutation performs no authentication or authorization checks before creating a customer portal session linked to any tenant Stripe account. An attacker can access and manage subscription data for any tenant without credentials.

Properties

severity
HIGH
score
8.6
epss_score
0.00424
cve_id
CVE-2026-72535
vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:L
published_at
2026-08-11T12:17:38.733
last_modified
2026-09-03T17:51:46.420
epss_percentile
0.35451

Related Entities (3)

ENRICHED_BY (1)

[Source]FIRST EPSS

DESCRIBED_BY (1)

[Source]NVD

HAS_WEAKNESS (1)

[Weakness]Missing Authentication for Critical Function

Explore deeper with Ninja Signal's threat intelligence graph

CVE-2026-72535 — Ninja Signal Threat Intelligence | Ninja Signal