VYPR
Medium severity5.9NVD Advisory· Published Sep 23, 2026· Updated Sep 23, 2026

CVE-2026-96599

CVE-2026-96599

Description

Isotope eCommerce through 2.9.10 derives order identifiers from uniqid() instead of a cryptographically secure source, allowing unauthenticated attackers to guess identifiers. Guest orders lack ownership verification, enabling attackers to access order details including billing address, customer information, and purchased files by supplying a guessed uid parameter.

Affected products

2

Patches

Vulnerability mechanics

References

4

News mentions

0

No linked articles in our index yet.