Sceawere
Vulnerability Detail
CVE-2026-19834UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
Webkul Bagisto Authorization Bypass
Vulnerability Metadata
- Severity
- Medium
- Score / CVSS
- 4.7
- Creation Date
- 2h ago
- Vendor
- Webkul
- Product
- Bagisto
- Attack Type
- Authorization Bypass
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:L
- Attack Complexity
- LOW
Narrative and Response
Description
A vulnerability was determined in Webkul Bagisto up to 2.4.4. Affected is an unknown function of the file /admin/customers/login-as-customer/ of the component Admin Customer Impersonation Feature. This manipulation of the argument ID causes authorization bypass. The attack can be initiated remotely. The exploit has been publicly disclosed and may be utilized. The vendor confirms: "The reported issues were already identified through our internal security assessment process prior to this notification and are being handled through our established internal security and development lifecycle. Some of these items have already been addressed, while the remaining items are planned for resolution in upcoming product releases."
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "4.7",
"pubDate": "2026-08-14T16:16:54.437Z",
"pubdate": "2026-08-14T16:16:54.437Z",
"executiveSummary": "An authorization bypass vulnerability has been identified in Webkul Bagisto up to version 2.4.4 within the Admin Customer Impersonation Feature. The vulnerability stems from improper handling of the argument ID in the endpoint /admin/customers/login-as-customer/. This security flaw enables remote attackers to execute unauthorized actions by manipulating parameter inputs, leading to broken access controls and potential unauthorized access to customer sessions or administrative privileges. The risk implication is significant as it compromises the confidentiality and integrity of user sessions within the e-commerce platform. The attack can be initiated remotely without requiring complex prerequisite access if valid interaction vectors or endpoints are reachable. The vendor has acknowledged the issue, stating that these items were identified through internal security assessments and are being addressed through their standard development lifecycle, with some fixes already implemented and others scheduled for upcoming product releases.",
"technicalDetails": "The vulnerability resides in the Admin Customer Impersonation Feature of Webkul Bagisto, specifically within the backend routing and controller logic handling requests sent to the /admin/customers/login-as-customer/ file path. The root cause of the vulnerability is an authorization bypass resulting from insufficient validation and verification of the argument ID supplied in the request payload. In a secure architecture, the application should rigorously validate that the authenticated administrative user possesses the necessary privileges and context to impersonate a specific target user ID, ensuring session tokens and privilege boundaries are strictly enforced. However, due to the flawed logic in the affected function, an attacker can manipulate the argument ID parameter to bypass access control checks.\nThe attack flow initiates remotely over the network when an adversary crafts an HTTP request targeting the /admin/customers/login-as-customer/ endpoint. By supplying an arbitrary or manipulated value within the argument ID parameter, the attacker circumvents the intended authorization checks designed to restrict customer impersonation capabilities to authorized administrative personnel. Upon processing the malicious input, the application fails to properly validate the session context against the requested identifier, resulting in the generation or authorization of a session belonging to the specified target user ID.\nThe affected versions include Webkul Bagisto up to version 2.4.4. The component responsible for the vulnerability is the Admin Customer Impersonation Feature. Exploitation requires network exposure to the administrative routing paths, though the exact authentication and privilege requirements may vary depending on how the endpoint handles initial session validation and whether partial or missing access controls allow unauthenticated or low-privileged interaction. The post-exploitation impact includes unauthorized session hijacking, impersonation of arbitrary users or customers within the platform, potential escalation of privileges, and unauthorized access to sensitive user data or functionalities associated with the targeted accounts."
}