
CVE-2026-25758 Spree is an open source e-commerce solution built with Ruby on Rails. A critical IDOR vulnerability exists in Spree Commerce's guest checkout flow that allows any gue… https://www.cve.org/CVERecord?id=CVE-2026-25758
Post summary
A critical IDOR flaw in Spree Commerce’s guest checkout flow is disclosed, allowing unauthorized actions, but no PoC, exploit, or patch details are included.
