CVE-2026-4549Disclosure

LOWCVSS 2.3 · LOW

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

A flaw has been found in mickasmt next-saas-stripe-starter 1.0.0. Affected by this issue is the function openCustomerPortal of the file actions/open-customer-portal.ts of the component Stripe API. This manipulation causes authorization bypass. Remote exploitation of the attack is possible. The complexity of an attack is rather high. The exploitation is known to be difficult.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-285CWE-639

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

STABLE

Threat summary

  • 3 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 2 signals
  • Disclosure: 2 classified signals
  • General: 1 classified signal
  • Peaked 1d ago at 2 mentions (2026-03-22); latest day: 1
  • 3 total mentions across 2 days

Deep dive

Activity timeline3 mentions / 2d
01122Mentions · 2026-03-22: 2Mentions · 2026-03-23: 1Technical Details · 2026-03-22: 203-2203-23
Signal classification2 categories
Disclosure
266.7%
General
133.3%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-03-222
Disclosure1General1
2026-03-231
Disclosure1
Full discourse3 posts
  • CVE@CVEnew
    Disclosure

    CVE-2026-4549 A flaw has been found in mickasmt next-saas-stripe-starter 1.0.0. Affected by this issue is the function openCustomerPortal of the file actions/open-customer-portal.ts … https://www.cve.org/CVERecord?id=CVE-2026-4549

    Post summary

    Announces the discovery of a flaw in mickasmt next-saas-stripe-starter, pointing to the affected function without further technical or mitigation details.

    0000096
    56.8K followersView on X
  • CyberDudeBivash® | Global Cybersecurity Company@cyberbivash
    General

    🚨 CYBERDUDEBIVASH SENTINEL APEX ALERT 🚨 Threat: CVE-2026-4549 - mickasmt next-saas-stripe-starter Stripe API open-customer-portal.ts openCustomerPortal authorization Intel Report: https://ift.tt/iPUXyKx

    Post summary

    The alert references CVE-2026-4549 affecting the Stripe API's openCustomerPortal authorization, but provides no PoC, exploit code, active exploitation evidence, or patch information.

    0000039
    292 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-4549 Authorization Bypass in Mickasmt Next-Saas-Stripe-Starter 1.0.0 Stripe API Component https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-4549

    Post summary

    CVE-2026-4549 is an authorization bypass vulnerability in Mickasmt Next-Saas-Stripe-Starter 1.0.0; the announcement provides minimal technical detail and lacks information on exploitation or patching.

    0000033
    4.0K followersView on X

Explore more