Back

LOW

mickasmt next-saas-stripe-starter Stripe API open-customer-portal.ts openCustomerPortal authorization

Published Mar 22, 2026

Description

A flaw has been found in mickasmt next-saas-stripe-starter 1.0.0. Affected by this issue is the function openCustomerPortal of the file actions/open-customer-portal.ts of the component Stripe API. This manipulation causes authorization bypass. Remote exploitation of the attack is possible. The complexity of an attack is rather high. The exploitation is known to be difficult.

Affected products

Remediation

No remediation recorded yet.

References (4)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner VulDB
Published Mar 22, 2026
Updated Mar 25, 2026
Reserved Mar 21, 2026
CISA Vulnrichment
Updated Mar 25, 2026
NVD
Status Deferred
Modified Jun 17, 2026
Red Hat
Severity n/a
Public date n/a
ENISA EUVD
Assigner VulDB
Published Mar 22, 2026
Updated Mar 25, 2026
Exploited since n/a
EUVD-2026-14308