Sceawere

Vulnerability Detail

CVE-2026-19838UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Webkul Bagisto Authorization Bypass

Vulnerability Metadata

Severity
Medium
Score / CVSS
4.3
Creation Date
1h ago
Vendor
Webkul
Product
Bagisto
Attack Type
Authorization Bypass
Vector String
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Attack Complexity
LOW

Narrative and Response

Description

A security vulnerability has been detected in Webkul Bagisto up to 2.4.4. This vulnerability affects unknown code of the file /admin/reporting/sales/ of the component Backend Reporting Endpoint. The manipulation leads to authorization bypass. Remote exploitation of the attack is possible. The exploit has been disclosed publicly and may be used. The vendor confirms: "The reported issues were already identified through our internal security assessment process prior to this notification and are being handled through our established internal security and development lifecycle. Some of these items have already been addressed, while the remaining items are planned for resolution in upcoming product releases."

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "4.3",
  "pubDate": "2026-08-14T17:17:34.267Z",
  "pubdate": "2026-08-14T17:17:34.267Z",
  "executiveSummary": "An authorization bypass vulnerability has been identified in Webkul Bagisto up to version 2.4.4, specifically residing within the backend reporting endpoint at the file path /admin/reporting/sales/ of the component Backend Reporting Endpoint. This security flaw introduces critical risk implications by allowing remote attackers to circumvent access control mechanisms protecting sensitive administrative analytics and reporting functionalities. The vulnerability stems from improper validation of user authorization states within the targeted endpoint. Exploitation of this flaw requires network connectivity to the administrative reporting interface, enabling remote unauthorized entities to interact with backend resources that should otherwise be restricted to authenticated and privileged administrative personnel. The impact of successful exploitation includes unauthorized access to sensitive sales reporting data and potential exposure of internal business intelligence metrics. The vendor has acknowledged the issue, noting that some related security items have already been addressed internally, with remaining items slated for resolution in upcoming product releases. Organizations utilizing vulnerable instances face potential exposure to information disclosure and unauthorized data access vectors if appropriate hardening or patching measures are not applied.",
  "technicalDetails": "The vulnerability is classified as an authorization bypass flaw impacting Webkul Bagisto up to version 2.4.4. The root cause of the issue originates from the Backend Reporting Endpoint, specifically within the execution flow handled by the file path /admin/reporting/sales/. In secure architectures, administrative endpoints enforce rigorous session validation, role-based access control (RBAC), and privilege verification checks to ensure that only authorized administrative users can query reporting components. However, in the affected versions, the application fails to adequately verify whether the incoming request originates from a legitimately authenticated session with the requisite administrative privileges before processing the reporting logic.\nThe attack flow proceeds as follows: a remote attacker crafts an HTTP request targeting the vulnerable /admin/reporting/sales/ file path. Due to the authorization bypass condition, the backend application processes the request and executes the underlying reporting functionality without verifying the security context or user session tokens. Consequently, the application bypasses access control enforcement and returns the requested sales reporting data directly to the client. This remote exploitation vector does not necessitate prior authentication or specialized administrative credentials, depending on how the access control checks fail at the endpoint level.\nThe network exposure of this vulnerability is remote, meaning that any attacker with network access to the web application interface can attempt to invoke the endpoint. The affected component is the Backend Reporting Endpoint, and affected versions include Webkul Bagisto up to 2.4.4. The post-exploitation impact primarily involves unauthorized viewing and retrieval of sensitive business metrics, sales analytics, and internal financial data exposed through the sales reporting interface, which can lead to further reconnaissance or compromise of business-critical information."
}
CVE-2026-19838: Webkul Bagisto Authorization Bypass (MEDIUM Severity, CVSS: 4.3) - Sceawere