Sceawere

Vulnerability Detail

CVE-2026-19993UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Webkul Bagisto RMA State Validation Workflow Enforcement

Vulnerability Metadata

Severity
Medium
Score / CVSS
4.3
Creation Date
3h ago
Vendor
Webkul
Product
Bagisto
Attack Type
Enforcement of Behavioral Workflow
Vector String
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
Attack Complexity
LOW

Narrative and Response

Description

A vulnerability has been found in Webkul Bagisto up to 2.4.4. Affected by this vulnerability is an unknown functionality of the file /customer/account/rma/update-status of the component RMA State Validation. The manipulation leads to enforcement of behavioral workflow. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The vendor confirms: "The reported issues were already identified through our internal security assessment process prior to this notification and are being handled through our established internal security and development lifecycle. Some of these items have already been addressed, while the remaining items are planned for resolution in upcoming product releases."

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "4.3",
  "pubDate": "2026-08-17T06:17:39.957Z",
  "pubdate": "2026-08-17T06:17:39.957Z",
  "executiveSummary": "A vulnerability has been identified in Webkul Bagisto up to version 2.4.4, specifically within the RMA State Validation component. The flaw involves improper handling and enforcement of behavioral workflows associated with Return Merchandise Authorization (RMA) status updates.\nThe vulnerability allows remote attackers to manipulate application logic and bypass intended business process constraints, leading to the unauthorized enforcement or alteration of behavioral workflows.\nThe affected system is the Webkul Bagisto e-commerce platform processing customer RMA requests. The security implications include potential integrity violations of transaction and return lifecycles, enabling malicious actors to force state transitions outside of valid operational parameters.\nExploitation of this vulnerability requires network access to the target application and the capability to issue HTTP requests to the vulnerable endpoint. The attack vector is fully remote, and public disclosure of the exploit increases the risk of active exploitation against unpatched deployments.\nThe vendor has acknowledged the issue, stating that these items were previously identified via internal security assessments and are being managed through standard development lifecycles, with some fixes already deployed and remaining items scheduled for upcoming releases.",
  "technicalDetails": "The vulnerability resides in the RMA State Validation component of Webkul Bagisto, specifically exposed via the file path /customer/account/rma/update-status.\nThe root cause stems from insufficient server-side validation and state machine enforcement during the processing of RMA status update requests. Web applications implementing complex business workflows must strictly validate state transitions against a deterministic state machine model. When state validation is inadequately enforced, clients can submit arbitrary parameters to force unauthorized transitions.\nAttack flow and exploitation mechanics occur via remote HTTP requests targeting the vulnerable /customer/account/rma/update-status endpoint. An authenticated or unauthenticated remote attacker (depending on authorization checks tied to the specific implementation context) crafts HTTP requests designed to manipulate the internal state variables of an RMA ticket.\nBy supplying manipulated state parameters, the attacker bypasses the sequential verification checks normally enforced by the application's business logic layer. This allows the payload to force the behavioral workflow into an inconsistent or unauthorized state.\nThe affected versions include Webkul Bagisto up to version 2.4.4. Network exposure is broad, as the endpoint is accessible via standard web protocols over HTTP/HTTPS. The post-exploitation impact includes the corruption of order and return workflows, potential unauthorized approvals or rejections of merchandise returns, and degradation of transactional integrity within the e-commerce platform."
}
CVE-2026-19993: Webkul Bagisto RMA State Validation Workflow Enforcement (MEDIUM Severity, CVSS: 4.3) - Sceawere