CVE-2026-31867: 
PHP vulnerability analysis and mitigation

Overview

CVE-2026-31867 is an Insecure Direct Object Reference (IDOR) vulnerability in Craft Commerce's cart functionality that allows unauthenticated attackers to hijack any shopping cart by knowing or guessing its 32-character cart number. It affects Craft Commerce versions 4.0.0–4.11.0 and 5.0.0–5.6.0, and was disclosed on March 9, 2026. The vulnerability carries a CVSS v3.1 base score of 4.8 (Medium) and a CVSS v4.0 base score of 6.3 (Medium) (GitHub Advisory).

Technical details

The root cause is classified as CWE-639 (Authorization Bypass Through User-Controlled Key). In CartController.php, both actionLoadCart() (lines 374–389) and the internal _getCart() method (lines 606–616) accept a user-supplied number parameter to retrieve shopping carts, but only verify that the order exists and is incomplete — no ownership or session binding check is performed. This means any requester who supplies a valid cart number can load and potentially modify that cart. Cart numbers can be obtained via referrer header leakage, browser history, proxy/WAF logs, social engineering, or targeted brute force against recently created carts (GitHub Advisory, GitHub PR).

Impact

Successful exploitation allows an attacker to hijack another user's active shopping session, gaining access to personally identifiable information (PII) stored in the cart such as billing/shipping addresses and email addresses. The attacker can also modify the victim's cart contents or disrupt the shopping session, impacting both confidentiality and availability of the cart data. The scope is limited to the Craft Commerce application layer and does not directly enable lateral movement to underlying infrastructure (GitHub Advisory).

Exploitability

No weaponized exploit or active in-the-wild exploitation has been reported. The GitHub Security Advisory includes source code snippets for analysis but no concrete exploit steps or crafted request payloads (GitHub Advisory). The EPSS score is approximately 0.041% (22nd percentile), indicating a low near-term exploitation probability. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog.

Exploitation steps

  1. Reconnaissance: Identify a target Craft Commerce installation running a vulnerable version (4.0.0–4.11.0 or 5.0.0–5.6.0) by inspecting HTTP response headers, page source, or Composer metadata.
  2. Obtain a cart number: Acquire a victim's 32-character cart number through one of the following vectors: monitoring referrer headers if cart URLs are shared externally, accessing browser history on a shared/compromised device, reviewing proxy or WAF logs where cart numbers appear in URL parameters, or social engineering (e.g., support tickets or screenshots containing cart URLs).
  3. Send a crafted request: Issue an HTTP GET or POST request to the commerce/cart/load-cart endpoint with the number parameter set to the victim's cart number (e.g., GET /actions/commerce/cart/load-cart?number=<32-char-hex>).
  4. Hijack the session: The CartController::actionLoadCart() method loads the cart into the attacker's session without any ownership validation, granting full access to the victim's cart contents, PII, and the ability to modify or complete the order (GitHub Advisory).

Indicators of compromise

  • Network: Unusual HTTP GET/POST requests to /actions/commerce/cart/load-cart or similar cart endpoints with number parameters not associated with the requesting user's session; requests originating from IPs inconsistent with the cart owner's session history.
  • Logs: Web server or application logs showing repeated or sequential cart number lookups from a single IP or session; access log entries for commerce/cart/load-cart where the number parameter differs from any cart previously associated with that session.
  • Application Behavior: Cart ownership changes without user-initiated action; unexpected PII (email, address) appearing in session data for anonymous or mismatched users.

Mitigation and workarounds

Upgrade Craft Commerce to version 4.11.0 (for the 4.x branch) or 5.6.0 (for the 5.x branch), which introduce token-based security for cart loading. The fix adds Craft's built-in cryptographic token system to generate time-limited, one-use cart load URLs; carts with email addresses or billing/shipping data now require a valid token or authenticated ownership before loading. A new cartLoadUrlExpiry setting (default: 7 days) controls token validity. No configuration-only workaround is available for unpatched versions — upgrading is the only remediation (GitHub Advisory, GitHub PR).

Community reactions

The vulnerability was reported by security researchers rlarabee and RajChowdhury240 and published by angrybrad on March 9, 2026. The fix was developed by the Craft CMS core team (lukeholder) and merged on June 3, 2026. No significant broader media coverage or notable public commentary beyond the GitHub advisory and pull request discussion has been identified (GitHub Advisory, GitHub PR).

Additional resources


Source: This report was generated using AI

Related PHP vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-55224HIGH8.7
  • PHP logoPHP
  • mineadmin/mineadmin
NoYesSep 30, 2026
CVE-2026-103111HIGH7.6
  • MariaDB Server logoMariaDB Server
  • mariadb11.8-server
NoYesSep 30, 2026
GHSA-3q6v-r5mr-hxv8HIGH7.5
  • PHP logoPHP
  • league/commonmark
NoYesSep 30, 2026
GHSA-97jj-33gv-5xf9MEDIUM6.1
  • PHP logoPHP
  • league/commonmark
NoYesSep 30, 2026
CVE-2026-104181MEDIUM5.4
  • PHP logoPHP
  • filament/filament
NoYesOct 01, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management