{"id":"CVE-2020-26223","aliases":["GHSA-m2jr-hmc3-qmpr"],"url":"https://o3.security/vulnerability/CVE-2020-26223","summary":"Authorization bypass in Spree","details":"### Impact\nThe perpetrator could query the [API v2 Order Status](https://guides.spreecommerce.org/api/v2/storefront#tag/Order-Status) endpoint with an empty string passed as an Order token\n\n### Patches\nPlease upgrade to 3.7.11, 4.0.4, or 4.1.11 depending on your used Spree version. Users of Spree < 3.7 are not affected.\n\n### References\nPull request with a fix and in-depth explanation - https://github.com/spree/spree/pull/10573\n\n### For more information\nIf you have any questions or comments about this advisory:\n* Email us at [security@spreecommerce.org](mailto:security@spreecommerce.org)","published":"2020-11-13T18:15:12.777Z","modified":"2026-07-09T02:49:22.473972Z","cvss":{"score":6.5,"severity":"MEDIUM","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N"},"epss":{"score":0.01124,"percentile":0.63741,"asOf":"2026-08-20"},"cisaKev":null,"exploitsKnown":1,"affectedPackages":[{"ecosystem":"RubyGems","name":"spree_api","fixedVersion":"3.7.13"},{"ecosystem":"RubyGems","name":"spree_api","fixedVersion":"4.0.5"},{"ecosystem":"RubyGems","name":"spree_api","fixedVersion":"4.1.12"}],"fix":{"url":"https://github.com/spree/spree/pull/10573","label":"spree/spree#10573"},"references":[{"type":"ADVISORY","url":"https://github.com/spree/spree/security/advisories/GHSA-m2jr-hmc3-qmpr"},{"type":"ADVISORY","url":"https://guides.spreecommerce.org/api/v2/storefront#tag/Order-Status"},{"type":"FIX","url":"https://github.com/spree/spree/pull/10573"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2020-26223"},{"type":"WEB","url":"https://github.com/rubysec/ruby-advisory-db/blob/master/gems/spree_api/CVE-2020-26223.yml"},{"type":"PACKAGE","url":"https://github.com/spree/spree"},{"type":"WEB","url":"https://rubygems.org/gems/spree_api/versions"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-07-09T02:49:22.473972Z"}}