Description
A vulnerability was detected in Webkul Bagisto up to 2.4.6. This impacts an unknown function of the file /admin/sales/invoices/mass-update/state of the component Invoice Mass Status Update. Performing a manipulation results in missing authorization. The attack can be initiated remotely. The exploit is now public and may be used. The vendor was contacted early about this disclosure.
Published: 2026-09-28
Score: 5.1 Medium
EPSS: n/a
KEV: No
Impact: Authorization Bypass
Action: Patch Now
AI Analysis

Impact

A flaw in Webkul Bagisto’s Invoice Mass Status Update endpoint allows an attacker to change the status of any invoice without proper authorization. The missing access checks let a remote user submit a request to /admin/sales/invoices/mass-update/state and alter invoice states, potentially creating fraudulent financial data. This vulnerability is rooted in Invalid Function Authorization and Privilege Validation weaknesses.

Affected Systems

Bagisto 2.4.6 and earlier versions are impacted. The flaw resides in the administrative sales invoices mass‑update component and affects users lacking sufficient rights to perform invoice status changes.

Risk and Exploitability

The score of 5.1 indicates a medium‑severity breach of integrity. Because the attack can be launched remotely and the exploit is publicly available, the risk is tangible, though the EPSS metric is unavailable. The vulnerability is not listed in the CISA KEV catalog. An attacker could craft a request to the target endpoint from any internet‑accessible location and induce unauthorized invoice state transitions.

Generated by OpenCVE AI on September 28, 2026 at 20:23 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Bagisto to version 2.4.7 or later, which contains the authorization fix for the mass status update route.
  • When upgrading is not immediately possible, restrict access to the /admin/sales/invoices/mass-update/state endpoint to users with administrative privileges and enforce role‑based access controls at the application level.
  • Configure the web server to require authentication for all /admin/* routes and monitor invoice‑status change logs for anomalous activity.

Generated by OpenCVE AI on September 28, 2026 at 20:23 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 28 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 28 Sep 2026 19:15:00 +0000

Type Values Removed Values Added
Description A vulnerability was detected in Webkul Bagisto up to 2.4.6. This impacts an unknown function of the file /admin/sales/invoices/mass-update/state of the component Invoice Mass Status Update. Performing a manipulation results in missing authorization. The attack can be initiated remotely. The exploit is now public and may be used. The vendor was contacted early about this disclosure.
Title Webkul Bagisto Invoice Mass Status Update state authorization
First Time appeared Webkul
Webkul bagisto
Weaknesses CWE-862
CWE-863
CPEs cpe:2.3:a:webkul:bagisto:*:*:*:*:*:*:*:*
Vendors & Products Webkul
Webkul bagisto
References
Metrics cvssV2_0

{'score': 3.3, 'vector': 'AV:N/AC:L/Au:M/C:N/I:P/A:N/E:POC/RL:ND/RC:UR'}

cvssV3_0

{'score': 2.7, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:N/E:P/RL:X/RC:R'}

cvssV3_1

{'score': 2.7, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:N/E:P/RL:X/RC:R'}

cvssV4_0

{'score': 5.1, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:P'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-09-28T19:26:19.616Z

Reserved: 2026-09-28T07:42:38.014Z

Link: CVE-2026-101139

cve-icon Vulnrichment

Updated: 2026-09-28T19:26:14.861Z

cve-icon NVD

Status : Received

Published: 2026-09-28T19:16:47.940

Modified: 2026-09-28T20:17:08.347

Link: CVE-2026-101139

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-28T20:30:06Z

Weaknesses