CVE-2026-55219
PHP Analyse et atténuation des vulnérabilités

Aperçu

CVE-2026-55219 is a race condition vulnerability in Paymenter's credit payment implementation that allows authenticated users to double-spend credits by paying multiple invoices with the same credit balance. The flaw exists in app/Livewire/Invoices/Show.php within the payWithCredit() function, affecting Paymenter versions up to and including 1.5.4. It was published on June 30, 2026, with a patch released in version 1.5.5. The vulnerability carries a CVSS v3.1 base score of 5.3 (Medium) (GitHub Advisory).

Détails techniques

The root cause is classified as CWE-362 (Concurrent Execution using Shared Resource with Improper Synchronization). The application calls lockForUpdate() — a pessimistic row lock — on the user's credit balance row outside of an active database transaction. In MySQL/MariaDB, row-level locks are only enforced within an explicit transaction; without one, the lock is silently ignored. As a result, two or more concurrent HTTP requests can simultaneously read the same credit balance, each independently determine it is sufficient, and both proceed to approve payment via ExtensionHelper::addPayment() (GitHub Advisory, Paymenter Advisory).

Impact

Successful exploitation allows any authenticated user with a valid credit balance to bypass balance restrictions and settle multiple pending invoices simultaneously at the cost of only a single invoice. Because payments are processed successfully through ExtensionHelper::addPayment(), the platform provisions the corresponding services or digital goods for each approved payment, resulting in direct financial loss or unauthorized resource acquisition for the platform operator. There is no confidentiality or availability impact; the integrity impact is high due to unauthorized manipulation of financial transaction records (GitHub Advisory).

Étapes d’exploitation

  1. Authenticate: Log in to a Paymenter instance (version ≤ 1.5.4) with a valid user account that holds a credit balance sufficient to pay at least one invoice.
  2. Identify target invoices: Locate two or more pending invoices whose individual costs are each within the available credit balance.
  3. Craft concurrent requests: Prepare multiple simultaneous HTTP POST requests targeting the payWithCredit() endpoint in app/Livewire/Invoices/Show.php, each referencing a different invoice ID.
  4. Race the requests: Use a tool such as curl with parallel execution, Python's asyncio/aiohttp, or a custom script to send all requests at the same millisecond, exploiting the window before any balance deduction is committed.
  5. Collect provisioned services: Because both requests read the same pre-deduction balance and both pass the sufficiency check, ExtensionHelper::addPayment() is called for each, provisioning services or digital goods for all invoices while only deducting the balance once (GitHub Advisory).

Indicateurs de compromis

  • Logs: Multiple successful payment log entries for different invoices within the same millisecond or sub-second window for the same user account; repeated calls to ExtensionHelper::addPayment() in application logs without corresponding balance deductions.
  • Database: Credit balance records showing a single deduction despite multiple invoices being marked as paid; invoice status tables reflecting multiple invoices paid simultaneously by the same user.
  • Application Behavior: Unexpected provisioning of multiple services or digital goods for a user whose credit balance should only cover one item (GitHub Advisory).

Atténuation et solutions de contournement

Upgrade Paymenter to version 1.5.5, which contains the fix for this vulnerability. The remediation wraps the credit payment logic in a proper database transaction so that lockForUpdate() is enforced correctly by MySQL/MariaDB. No configuration-based workaround is documented; upgrading is the only recommended remediation (GitHub Advisory, Paymenter Advisory).

Ressources additionnelles


SourceCe rapport a été généré à l’aide de l’IA

Apparenté PHP Vulnérabilités:

Identifiant CVE

Sévérité

Score

Technologies

Nom du composant

Exploit CISA KEV

A corrigé

Date de publication

GHSA-h95v-h523-3mw8MEDIUM5.9
  • PHP logoPHP
  • guzzlehttp/guzzle
NonOuiJul 20, 2026
GHSA-wm3w-8rrp-j577MEDIUM5.9
  • PHP logoPHP
  • guzzlehttp/guzzle
NonOuiJul 20, 2026
GHSA-f283-ghqc-fg79MEDIUM5.3
  • PHP logoPHP
  • guzzlehttp/guzzle
NonOuiJul 20, 2026
GHSA-94pj-82f3-465wMEDIUM5.3
  • PHP logoPHP
  • guzzlehttp/guzzle
NonOuiJul 20, 2026
CVE-2026-55219MEDIUM5.3
  • PHP logoPHP
  • paymenter/paymenter
NonOuiJul 20, 2026

Évaluation gratuite des vulnérabilités

Évaluez votre posture de sécurité dans le cloud

Évaluez vos pratiques de sécurité cloud dans 9 domaines de sécurité pour évaluer votre niveau de risque et identifier les failles dans vos défenses.

Demander une évaluation

Obtenez une démo personnalisée

Prêt(e) à voir Wiz en action ?

"La meilleure expérience utilisateur que j’ai jamais vue, offre une visibilité totale sur les workloads cloud."
David EstlickRSSI
"Wiz fournit une interface unique pour voir ce qui se passe dans nos environnements cloud."
Adam FletcherChef du service de sécurité
"Nous savons que si Wiz identifie quelque chose comme critique, c’est qu’il l’est réellement."
Greg PoniatowskiResponsable de la gestion des menaces et des vulnérabilités