Sceawere

Vulnerability Detail

CVE-2026-19994UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Webkul Bagisto Authorization Bypass Vulnerability

Vulnerability Metadata

Severity
Medium
Score / CVSS
6.3
Creation Date
3h ago
Vendor
Webkul
Product
Bagisto
Attack Type
Authorization Bypass
Vector String
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
Attack Complexity
LOW

Narrative and Response

Description

A vulnerability was found in Webkul Bagisto up to 2.4.4. Affected by this issue is some unknown functionality of the file /admin/configuration/cache-management/execute of the component Configuration Management. The manipulation of the argument action results in authorization bypass. The attack may be launched remotely. The exploit has been made public and could be used. The vendor confirms: "The reported issues were already identified through our internal security assessment process prior to this notification and are being handled through our established internal security and development lifecycle. Some of these items have already been addressed, while the remaining items are planned for resolution in upcoming product releases."

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "6.3",
  "pubDate": "2026-08-17T07:17:15.150Z",
  "pubdate": "2026-08-17T07:17:15.150Z",
  "executiveSummary": "An authorization bypass vulnerability has been identified in Webkul Bagisto up to version 2.4.4, specifically within the Configuration Management component.\nThe vulnerability resides in the endpoint /admin/configuration/cache-management/execute and is triggered via the manipulation of the action argument.\nThis security flaw allows remote attackers to bypass access control mechanisms and execute unauthorized administrative functionalities associated with cache management.\nThe exploitation of this issue can lead to unauthorized system state modifications, potentially impacting application availability and integrity.\nPublicly available exploit code increases the risk of active exploitation in the wild.\nThe vendor has acknowledged the issue, stating that these findings overlap with internal security assessments and are being remediated through standard development lifecycles.",
  "technicalDetails": "The vulnerability is an authorization bypass flaw affecting Webkul Bagisto versions up to 2.4.4.\nThe vulnerable component is the Configuration Management module, specifically exposed via the HTTP route /admin/configuration/cache-management/execute.\nThe root cause stems from improper access control validation and inadequate input verification on the action argument submitted to the execution endpoint.\nAn attacker can exploit this vulnerability remotely by sending a crafted HTTP request to the target application.\nBy manipulating the action parameter within the request, an unauthorized user can bypass functional permission checks designed to restrict administrative operations.\nThe attack flow involves crafting a payload targeting the cache-management execution handler, bypassing authentication or privilege verification gates, and forcing the backend application logic to execute privileged cache operations.\nBecause the exploit requires network exposure of the administrative routing interface, any externally accessible instance of Bagisto running vulnerable code is at risk.\nSuccessful exploitation allows unauthorized actors to invoke internal administrative procedures without possessing the requisite administrative roles or privileges.\nThe post-exploitation impact includes unauthorized manipulation of system caching layers, which may lead to denial of service conditions, forced cache clearing, or disruption of application performance and data consistency."
}
CVE-2026-19994: Webkul Bagisto Authorization Bypass Vulnerability (MEDIUM Severity, CVSS: 6.3) - Sceawere