Description
CubeCart is an ecommerce software solution. Prior to 6.7.5, the delete-note handler in admin/sources/orders.index.inc.php verifies only the presence of order_id and delete-note parameters before deleting records from CubeCart_order_notes, without requiring CC_PERM_DELETE for orders. An authenticated administrator lacking order modification privileges can directly invoke the handler with valid identifiers and delete order-history notes, removing operational records and audit-trail data. This issue is fixed in version 6.7.5.
Published: 2026-09-17
Score: 5.4 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Unauthorized deletion of order history notes
Action: Apply patch
AI Analysis

Impact

CubeCart modules allow an authenticated administrator to delete order history notes without checking the required delete permission for orders. When a request contains an order_id and delete-note parameter, the handler immediately removes the note record from CubeCart_order_notes, effectively erasing audit trail data. This flaw is an authorization bypass that can result in loss of historical transaction information and hampers accountability.

Affected Systems

The vulnerability affects CubeCart v6, specifically all releases prior to 6.7.5.

Risk and Exploitability

The CVSS score of 5.4 indicates a moderate impact. The EPSS score is less than 1%, suggesting a very low probability of exploitation at this time. The flaw is not listed in CISA’s KEV catalog. The likely attack route requires an authenticated administrator who lacks edit privileges for orders; from the public or internal network the attacker can invoke the vulnerable handler directly, but no remote code execution or privilege escalation is granted. Consequently, the risk to confidentiality or integrity is limited to the deletion of audit data, but it undermines system integrity and regulatory compliance.

Generated by OpenCVE AI on September 19, 2026 at 01:17 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade CubeCart to v6.7.5 or later, which enforces CC_PERM_DELETE for order note deletion.
  • Ensure that the delete-note handler verifies both the presence of order_id and delete-note parameters and the CC_PERM_DELETE permission before performing the delete operation.
  • Restrict access to the admin/sources/orders.index.inc.php script or add role‑based access controls at the web server or application level to prevent direct invocation from unauthorized sources.

Generated by OpenCVE AI on September 19, 2026 at 01:17 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 20 Sep 2026 03:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 18 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
First Time appeared Cubecart
Cubecart v6
Vendors & Products Cubecart
Cubecart v6

Thu, 17 Sep 2026 22:15:00 +0000

Type Values Removed Values Added
Description CubeCart is an ecommerce software solution. Prior to 6.7.5, the delete-note handler in admin/sources/orders.index.inc.php verifies only the presence of order_id and delete-note parameters before deleting records from CubeCart_order_notes, without requiring CC_PERM_DELETE for orders. An authenticated administrator lacking order modification privileges can directly invoke the handler with valid identifiers and delete order-history notes, removing operational records and audit-trail data. This issue is fixed in version 6.7.5.
Title CubeCart: Missing Authorization Check for Order Note Deletion in orders.index.inc.php
Weaknesses CWE-862
References
Metrics cvssV3_1

{'score': 5.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-09-18T13:06:13.667Z

Reserved: 2026-06-15T20:16:46.198Z

Link: CVE-2026-54643

cve-icon Vulnrichment

Updated: 2026-09-18T13:06:02.316Z

cve-icon NVD

Status : Deferred

Published: 2026-09-17T22:17:02.147

Modified: 2026-09-23T19:43:31.933

Link: CVE-2026-54643

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-19T01:30:17Z

Weaknesses