PatchSiren

CoreUnion CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

MEDIUM CoreUnion CVE published 2026-10-11

CVE-2026-108696

CVE-2026-108696 is a medium-severity authorization bypass vulnerability in CoreShop versions up to 1.5.5. The issue allows authenticated customers to act on other customers' orders by manipulating user-controlled IDs in the OrderController's OrderConfirm and SendReship methods. This vulnerability can lead to unauthorized order modifications and overwriting of return tracking details. E-commerce site admin [truncated]