PT-2026-44944 · Shopper · Shopper

Baradika

·

Published

2026-05-29

·

Updated

2026-06-08

·

CVE-2026-47744

CVSS v3.1

9.9

Critical

VectorAV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Shopper versions prior to 2.8.0
Description Two authorization defects in the team settings allow an authenticated user to compromise the Role-Based Access Control (RBAC) system. The endpoint "Settings/Team/Index" lacks mount() authorization, enabling any authenticated user to access the page and utilize public actions to create new roles or delete other users, including administrators. Additionally, the endpoint "Settings/Team/RolePermission" restricts write actions using the read-only view users permission. Consequently, any user with view users can grant arbitrary permissions, such as manage users and edit orders, to themselves or others, escalating their privileges to full panel administrator. Together, these flaws allow a low-privilege user to gain administrator rights and remove legitimate administrators.
Recommendations Update to version 2.8.0.

Fix

Improper Authorization

Improper Privilege Management

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-47744
GHSA-C3QP-2GGW-XJG7

Affected Products

Shopper