A vulnerability, which was classified as problematic, was found in Paymenter up to 1.4.x. The affected element is an unknown function of the component ticket creation endpoint. The manipulation of the argument service ID results in authorization bypass.

This vulnerability is known as CVE-2026-44585. It is possible to launch the attack remotely. No exploit is available.