Sceawere

Vulnerability Detail

CVE-2026-75081UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Webkul Bagisto Workflow Enforcement Bypass

Vulnerability Metadata

Severity
Medium
Score / CVSS
4.3
Creation Date
3h ago
Vendor
Webkul
Product
Bagisto
Attack Type
Enforcement of Behavioral Workflow
Vector String
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
Attack Complexity
LOW

Narrative and Response

Description

A vulnerability was detected in Webkul Bagisto up to 2.4.4. Impacted is an unknown function of the file /customer/account/rma/store. The manipulation of the argument rma_qty/resolution_type/rma_reason_id results in enforcement of behavioral workflow. The attack may be performed from remote. The exploit is now public and may be used. The vendor confirms: "The reported issues were already identified through our internal security assessment process prior to this notification and are being handled through our established internal security and development lifecycle. Some of these items have already been addressed, while the remaining items are planned for resolution in upcoming product releases."

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "4.3",
  "pubDate": "2026-08-18T00:16:53.710Z",
  "pubdate": "2026-08-18T00:16:53.710Z",
  "executiveSummary": "A vulnerability has been identified in Webkul Bagisto up to version 2.4.4, specifically within the RMA management component. The vulnerability involves improper enforcement of behavioral workflows related to Return Merchandise Authorization (RMA) processing. An unauthenticated or remote attacker can manipulate specific input parameters during the RMA creation or modification lifecycle to bypass intended business logic and transactional constraints.\nThe impact of this security flaw includes unauthorized state transitions and manipulation of return quantities, resolution types, and reason identifiers, which could lead to inventory discrepancies, financial abuse, or unauthorized return processing. The vulnerability is exploitable remotely over the network without requiring complex preconditions, as public exploits are currently available.\nThe risk implications are moderate to high depending on the extent of business logic bypass achieved by the adversary, as it directly impacts order integrity and e-commerce transactional workflows. The vendor has acknowledged the issue, stating that these items were previously identified via internal security assessments and are being remediated through standard development lifecycles and upcoming product releases.",
  "technicalDetails": "The vulnerability resides within the RMA management subsystem of Webkul Bagisto, specifically targeting the backend controller processing requests directed to the file path /customer/account/rma/store. This endpoint is responsible for handling RMA submissions and storing return-related data parameters submitted by users.\nThe root cause stems from insufficient server-side validation and state verification of business logic workflows when handling specific transactional input arguments. Specifically, the manipulation of parameters including rma_qty, resolution_type, and rma_reason_id allows a remote threat actor to bypass the strict sequential or conditional constraints enforced by the application's standard behavioral workflow.\nFrom an attack flow perspective, a remote attacker initiates an HTTP request targeting the vulnerable /customer/account/rma/store endpoint. By supplying crafted values for rma_qty, resolution_type, and rma_reason_id, the adversary forces the application to accept unauthorized states, quantities, or resolution workflows that would typically be blocked or restricted under normal operational parameters. The input parameters are processed by the underlying application logic without adequate validation against the current order status, purchased quantities, or allowed product resolution paths.\nThe affected component is the RMA store controller and associated business logic handlers within Webkul Bagisto versions up to 2.4.4. The attack can be performed remotely over standard web protocols (HTTP/HTTPS). Depending on the specific configuration, authentication and privilege requirements may vary, but the vector is exposed to users interacting with the customer account portal. The post-exploitation impact includes unauthorized workflow execution, circumvention of return policies, potential inventory manipulation, and fraudulent processing of store credits or refunds."
}
CVE-2026-75081: Webkul Bagisto Workflow Enforcement Bypass (MEDIUM Severity, CVSS: 4.3) - Sceawere