Sceawere

Vulnerability Detail

CVE-2026-19835UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Webkul Bagisto Improper Access Control Vulnerability

Vulnerability Metadata

Severity
Low
Score / CVSS
3.8
Creation Date
2h ago
Vendor
Webkul
Product
Bagisto
Attack Type
Improper Access Controls
Vector String
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:L
Attack Complexity
LOW

Narrative and Response

Description

A vulnerability was identified in Webkul Bagisto up to 2.4.4. Affected by this vulnerability is an unknown functionality of the component Customer Item Deletion Endpoint. Such manipulation leads to improper access controls. The attack can be launched remotely. The exploit is publicly available and might be used. The vendor confirms: "The reported issues were already identified through our internal security assessment process prior to this notification and are being handled through our established internal security and development lifecycle. Some of these items have already been addressed, while the remaining items are planned for resolution in upcoming product releases."

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "3.8",
  "pubDate": "2026-08-14T16:16:54.593Z",
  "pubdate": "2026-08-14T16:16:54.593Z",
  "executiveSummary": "An improper access control vulnerability has been identified in Webkul Bagisto up to version 2.4.4, specifically residing within the Customer Item Deletion Endpoint component. This security flaw stems from insufficient authorization checks, allowing remote attackers to interact with sensitive functionalities without proper validation of user privileges. The vulnerability presents significant risk implications as exploitation can lead to unauthorized deletion of items belonging to other users or system entities, compromising data integrity and confidentiality within the e-commerce platform. The attack vector is remote, meaning that malicious actors do not require prior physical access to the target system to initiate exploitation. Furthermore, proof-of-concept exploits are publicly available, increasing the likelihood of active exploitation in the wild. While the vendor has acknowledged the issue and stated that internal security assessments identified related problems for resolution in upcoming product releases, users operating vulnerable versions remain exposed unless compensating controls or direct software patches are applied. The combination of remote accessibility, public exploit availability, and direct impact on core transactional components underscores the critical need for immediate remediation.",
  "technicalDetails": "The vulnerability is categorized as an improper access control issue affecting the Customer Item Deletion Endpoint within Webkul Bagisto up to version 2.4.4. Root cause analysis indicates that the endpoint fails to adequately verify whether the authenticated or unauthenticated session context possesses the necessary administrative or ownership privileges required to execute item deletion requests. Consequently, an attacker can manipulate parameters sent to the vulnerable endpoint to bypass intended security boundaries.\nThe attack flow begins with the reconnaissance phase, where an attacker identifies the target Webkul Bagisto deployment and locates the Customer Item Deletion Endpoint. Because the vulnerability is exposed over the network, the attacker crafts a malicious HTTP request targeting this specific endpoint. Depending on the exact implementation details and session handling mechanisms of the target instance, the request may be issued remotely without requiring high-privileged authentication, or by leveraging a low-privileged customer account to target resources outside their authorization scope. The payload typically involves supplying manipulated identifiers, such as target item or customer IDs, within the request parameters.\nUpon receiving the malicious request, the vulnerable component processes the deletion logic without performing adequate server-side validation to ensure that the requester is authorized to modify or delete the specified resource. This results in the unauthorized execution of deletion operations against arbitrary items within the database. The post-exploitation impact includes severe data loss, disruption of e-commerce operations, and potential cascading integrity failures across related system components.\nAffected versions include all releases of Webkul Bagisto up to 2.4.4. Remediation efforts depend on vendor-supplied patches, as internal security processes are actively addressing these items in upcoming product releases. Administrators are advised to monitor official vendor channels for patch availability and apply updates promptly."
}
CVE-2026-19835: Webkul Bagisto Improper Access Control Vulnerability (LOW Severity, CVSS: 3.8) - Sceawere