CVE-2026-47198Disclosure

LOWCVSS 8.5 · HIGH

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

Paymenter is a free and open-source webshop solution for management of hosting services. In versions prior to 1.5.1, the checkout component improperly filters URL-writable properties, allowing authenticated users to inject arbitrary key-value pairs into server provisioning parameters. Because bundled server extensions prioritize these user-supplied properties over administrator-defined configurations, a regular user can override hosting plans and resource limits at checkout without special privileges. The Checkout Livewire component's $checkoutConfig property exposed via URL query parameters, only validating keys explicitly defined by an extension's configuration method, allowing any undefined injected keys to bypass validation entirely. These unsanitized keys are then stored directly in the database by the cart component and later passed to server extensions during provisioning, enabling user-injected data to override intended administrator settings. Depending on the active extension, this leads to unauthorized overrides of core resource limits (such as CPU, RAM, storage, or package tiers). No administrative privileges are required to exploit this vulnerability. This issue has been fixed in version 1.5.1.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-20CWE-639

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

STABLE

Threat summary

  • 4 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 3 signals
  • Disclosure: 4 classified signals
  • Peaked 1d ago at 2 mentions (2026-06-30); latest day: 2
  • 4 total mentions across 2 days

Deep dive

Activity timeline4 mentions / 2d
01122Mentions · 2026-06-30: 2Mentions · 2026-07-20: 2Technical Details · 2026-06-30: 2Technical Details · 2026-07-20: 106-3007-20
Signal classification1 categories
Disclosure
4100.0%
Referenced assets3 URLs
Full discourse4 posts
  • CVE@CVEnew
    Disclosure

    CVE-2026-47198 Paymenter is a free and open-source webshop solution for management of hosting services. In versions prior to 1.5.1, the checkout component improperly filters URL-wri… https://www.cve.org/CVERecord?id=CVE-2026-47198

    Post summary

    The text notes that versions of Paymenter prior to 1.5.1 contain a vulnerability involving improper URL filtering, but it contains no further details, no PoC, or patch information.

    100311.2K
    58.1K followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-47198 Paymenter is a free and open-source webshop solution for management of hosting services. In versions prior to 1.5.1, the checkout component improperly filters URL-wri… https://www.cve.org/CVERecord?id=CVE-2026-47198 ----- Traducción: CVE-2026-47198 Pay… http://infoflow.cloud`

    Post summary

    The tweet announces the existence of CVE-2026-47198 for Paymenter, describing a specific flaw in the checkout component, but does not provide PoC, exploit, or patch details.

    0000029
    93 followersView on X
  • Upwind Security MDR@UpwindMDR
    Disclosure

    🚨 HIGH - Paymenter checkout parameter injection enables provisioning override (CVE-2026-47198) Paymenter’s checkout flow in paymenter/paymenter improperly filters URL-writable properties, letting authenticated users inject arbitrary key-value pairs into server provisioning parameters. The root cause is improper input validation/mass assignment of user-controlled fields, where undefined keys bypass validation and are stored without sanitization. An attacker exploits this by submitting crafted checkout requests while logged in, adding unexpected parameter names that later get consumed during provisioning and can override admin-defined settings. Impact includes unauthorized changes to resource limits (CPU/RAM/storage), bypassing paid plan restrictions, and potential abuse of infrastructure allocation without administrative privileges. 👉 Affected: paymenter/paymenter (versions not specified; assume all prior to fix) | Upgrade to No fix yet — treat as suspicious

    Post summary

    The post discloses CVE‑2026‑47198, detailing a parameter injection flaw that lets authenticated users alter server provisioning settings, but no exploitation code, PoC, or patch is provided.

    0000064
    232 followersView on X
  • DailyCVE@dailycve
    Disclosure

    🟠 Paymenter, Improper Input Validation, #CVE-2026-47198 (Medium) -DC-Jun2026-743 https://dailycve.com/paymenter-improper-input-validation-cve-2026-47198-medium-dc-jun2026-743/

    Post summary

    A new medium‑severity vulnerability, CVE‑2026‑47198, has been disclosed in Paymenter involving improper input validation.

    0000058
    217 followersView on X

Explore more