A vulnerability was found in crater-invoice Crater 6.0.6. It has been declared as critical. Affected by this issue is the function
Customer::deleteCustomers of the component CustomerPolicy. The manipulation results in improper privilege management.
This vulnerability is reported as CVE-2026-55739. The attack can be launched remotely. No exploit exists.