PT-2026-1125 · Bagisto · Bagisto
Mhzcyber
·
Published
2026-01-02
·
Updated
2026-01-03
·
CVE-2026-21446
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Bagisto versions prior to 2.3.10
Description
Bagisto, an open source Laravel eCommerce platform, has an issue where API routes remain active even after the initial installation is complete. The API endpoints (
/install/api/*) are directly accessible and exploitable without authentication. This allows an unauthenticated attacker to bypass the installer and create admin accounts, modify application configurations, and potentially overwrite existing data.Recommendations
Update to version 2.3.10 or later.
Exploit
Fix
Missing Authentication
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Bagisto