Two application-layer vulnerabilities were disclosed affecting monetr and Craft Commerce, exposing different classes of business risk. In CVE-2026-39901, monetr contains an authorization bypass and transaction-integrity flaw that lets a low-privileged user, with user interaction, selectively hide imported bank transactions. Although the records are only soft-deleted in the database, they disappear from application views and calculations, causing inaccurate balances and reports; the issue was scored CVSS v3.1 5.7 (Medium) and tied to inconsistent authorization checks across HTTP methods on the same resource.
In CVE-2026-32270, a flaw in the Craft Commerce payments controller can disclose customer personally identifiable information, including names, email addresses, shipping and billing addresses, and purchase histories, when an attacker can obtain a valid order number. The exposure is more practical where applications use predictable or sequential order identifiers, while high-entropy values such as UUIDv4 materially reduce exploitability; the issue was assigned CVSS 4.0 1.7, reflecting low attack complexity, no required privileges, and impact limited to confidentiality.

See affected versions and whether adversaries are exploiting it.
2 events from the most recent confirmed update back to the earliest known activity.
A vulnerability in the Craft Commerce Payments Controller was publicly documented as CVE-2026-32270. The issue can expose customer personal information such as names, email addresses, addresses, and purchase history when a valid order number is obtained.
A vulnerability affecting the monetr budgeting application was publicly documented as CVE-2026-39901. The flaw allows a low-privileged user, with user interaction, to hide imported bank transactions from application views and calculations, creating a transaction integrity issue.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
2 references tracked. Mallory keeps watching after this page renders.
cvereports.com
Open sourcecvereports.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.