{"id":"CVE-2026-59805","title":"Gumroad before 2026.07.06.2 contains a broken access control vulnerability in the PurchasesController that allows authenticated sellers to manipulate purchase access for other sellers' products by sending PUT requests to the revoke_acces…","summary":"Gumroad before 2026.07.06.2 contains a broken access control vulnerability in the PurchasesController that allows authenticated sellers to manipulate purchase access for other sellers' products by sending PUT requests to the revoke_acces…","severity":"medium","cvss":6.5,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N","cwe":["CWE-862"],"vendor":"antiwork","product":"gumroad","affected":["gumroad < 2026.07.06.2"],"published":"2026-07-08","updated":"2026-10-08","sourceUpdated":"2026-10-08T16:17:24.287","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-59805","references":[{"url":"https://github.com/antiwork/gumroad/commit/e7fd0e610e73135ecf1aa07c197a36fa524832e1","label":"disclosure@vulncheck.com"},{"url":"https://github.com/antiwork/gumroad/issues/5725","label":"disclosure@vulncheck.com"},{"url":"https://github.com/antiwork/gumroad/pull/5731","label":"disclosure@vulncheck.com"},{"url":"https://github.com/antiwork/gumroad/releases/tag/v2026.07.06.2","label":"disclosure@vulncheck.com"},{"url":"https://www.vulncheck.com/advisories/gumroad-insecure-direct-object-reference-in-purchasescontroller","label":"disclosure@vulncheck.com"}],"tags":["nvd","cve.org"],"ssvc":{"exploitation":"none","automatable":"no","technicalImpact":"partial","timestamp":"2026-07-09T13:37:43.271098Z"},"epss":0.00389,"epssPercentile":0.30805,"ingestedAt":"2026-10-08T16:52:14.696Z","slug":"CVE-2026-59805","body":"## Overview\n\nGumroad before 2026.07.06.2 contains a broken access control vulnerability in the PurchasesController that allows authenticated sellers to manipulate purchase access for other sellers' products by sending PUT requests to the revoke_access and undo_revoke_access actions without seller ownership validation. Attackers can modify the is_access_revoked status on arbitrary purchases to unauthorized revoke or restore buyer access to products they do not own.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"sunlit","depthScore":36,"depthScoreParts":{"impact":35.8,"likelihood":0.1,"exploitation":0,"ransomware":0},"changes":[]}