Sceawere

Vulnerability Detail

CVE-2026-19836UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Webkul Bagisto Authorization Bypass

Vulnerability Metadata

Severity
Medium
Score / CVSS
4.3
Creation Date
2h ago
Vendor
Webkul
Product
Bagisto
Attack Type
Authorization Bypass
Vector String
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Attack Complexity
LOW

Narrative and Response

Description

A security flaw has been discovered in Webkul Bagisto up to 2.4.4. Affected by this issue is some unknown functionality of the file /admin/customers/view of the component Backend Customer Detail Feature. Performing a manipulation of the argument ID results in authorization bypass. The attack may be initiated remotely. The exploit has been released to the public and may be used for attacks. The vendor confirms: "The reported issues were already identified through our internal security assessment process prior to this notification and are being handled through our established internal security and development lifecycle. Some of these items have already been addressed, while the remaining items are planned for resolution in upcoming product releases."

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "4.3",
  "pubDate": "2026-08-14T16:16:54.743Z",
  "pubdate": "2026-08-14T16:16:54.743Z",
  "executiveSummary": "An authorization bypass vulnerability has been identified in Webkul Bagisto up to version 2.4.4, specifically within the Backend Customer Detail Feature. The flaw resides in the handling of the administrative customer view functionality located at the endpoint /admin/customers/view. By manipulating the identifier argument, unauthorized remote threat actors may bypass access control mechanisms to view or interact with sensitive customer data without proper authorization. This security flaw introduces significant risk regarding data confidentiality and integrity within administrative contexts. The attack can be initiated remotely by malicious actors interacting with the exposed web interface. Although the vendor has acknowledged the issue and indicates that internal remediation processes are underway or partially completed, the public availability of exploit details increases the probability of active exploitation in the wild. Organizations utilizing affected instances face potential unauthorized data access, necessitating immediate vigilance, application monitoring, and application of official vendor patches as soon as they become available.",
  "technicalDetails": "The vulnerability is classified as an authorization bypass resulting from insufficient access control enforcement within the Backend Customer Detail Feature of Webkul Bagisto up to version 2.4.4. The affected component processes administrative requests via the specific file path /admin/customers/view. The core root cause stems from inadequate validation or verification of user permissions and session context relative to the requested resource identifier parameter (ID). Specifically, the application fails to properly verify whether the authenticated or unauthenticated session possesses the requisite administrative privileges to access the specific customer record requested via the manipulated ID argument. The exploitation method relies on parameter tampering, where an attacker modifies the target identifier within the request payload to reference arbitrary records. The attack flow begins with the threat actor formulating an HTTP request directed at the vulnerable /admin/customers/view endpoint. By systematically altering the ID parameter within the request query string or body, the remote attacker bypasses application-layer authorization checks designed to restrict data access to authorized administrative personnel. Because the vulnerability is exposed over the network, it requires no physical access and can be automated via scripts to harvest sensitive customer records enumeration-style. Post-exploitation impact includes unauthorized disclosure of personally identifiable information (PII) and potentially administrative state corruption depending on the downstream functionality tied to the customer detail view. Authentication and privilege requirements vary based on the specific entry point context, but the vulnerability fundamentally represents a breakdown in secure direct object reference (IDOR) handling or role-based access control (RBAC) enforcement within the administrative routing logic. Network exposure is high, as the application interface is typically accessible over standard web ports (HTTP/HTTPS) from the Internet."
}
CVE-2026-19836: Webkul Bagisto Authorization Bypass (MEDIUM Severity, CVSS: 4.3) - Sceawere