Description
A vulnerability was identified in Webkul Bagisto up to 2.4.4. Affected by this vulnerability is an unknown functionality of the component Customer Item Deletion Endpoint. Such manipulation leads to improper access controls. The attack can be launched remotely. The exploit is publicly available and might be used. The vendor confirms: "The reported issues were already identified through our internal security assessment process prior to this notification and are being handled through our established internal security and development lifecycle. Some of these items have already been addressed, while the remaining items are planned for resolution in upcoming product releases."
Published: 2026-08-14
Score: 5.1 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability in Webkul Bagisto allows a remote attacker to delete customer items through the Customer Item Deletion Endpoint because the system lacks proper authorization checks. This improper access control exposes the application to unauthorized data modification and loss, compromising data integrity. The weakness is classified as CWE‑266 and CWE‑284.

Affected Systems

Webkul Bagisto versions up to and including 2.4.4 are affected. Any deployment of these versions that has not received the vendor’s security update remains susceptible to exploitation.

Risk and Exploitability

The CVSS score of 5.1 indicates a moderate risk. The exploit is publicly available, and the attack can be launched remotely without requiring special privileges. With no EPSS score available and the vulnerability not listed in the CISA KEV catalog, the likelihood of widespread exploitation is currently limited; however, the presence of a publicly known exploit warrants timely remediation.

Generated by OpenCVE AI on August 14, 2026 at 17:25 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade to the latest Bagisto release that incorporates the fix for the Customer Item Deletion Endpoint.
  • If an upgrade is not yet possible, modify the application configuration or code to restrict the deletion functionality so that only users with administrative privileges can trigger delete requests.
  • Deploy a web application firewall or reverse proxy rule to block unauthorized deletion requests and monitor application logs for any attempts to delete customer items.

Generated by OpenCVE AI on August 14, 2026 at 17:25 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 14 Aug 2026 15:30:00 +0000

Type Values Removed Values Added
Description A vulnerability was identified in Webkul Bagisto up to 2.4.4. Affected by this vulnerability is an unknown functionality of the component Customer Item Deletion Endpoint. Such manipulation leads to improper access controls. The attack can be launched remotely. The exploit is publicly available and might be used. The vendor confirms: "The reported issues were already identified through our internal security assessment process prior to this notification and are being handled through our established internal security and development lifecycle. Some of these items have already been addressed, while the remaining items are planned for resolution in upcoming product releases."
Title Webkul Bagisto Customer Item Deletion Endpoint access control
First Time appeared Webkul
Webkul bagisto
Weaknesses CWE-266
CWE-284
CPEs cpe:2.3:a:webkul:bagisto:*:*:*:*:*:*:*:*
Vendors & Products Webkul
Webkul bagisto
References
Metrics cvssV2_0

{'score': 4.7, 'vector': 'AV:N/AC:L/Au:M/C:N/I:P/A:P/E:POC/RL:ND/RC:UR'}

cvssV3_0

{'score': 3.8, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:L/E:P/RL:X/RC:R'}

cvssV3_1

{'score': 3.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:L/E:P/RL:X/RC:R'}

cvssV4_0

{'score': 5.1, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N/E:P'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-08-14T16:09:35.282Z

Reserved: 2026-08-14T07:44:18.783Z

Link: CVE-2026-19835

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Deferred

Published: 2026-08-14T16:16:54.593

Modified: 2026-08-14T19:09:39.140

Link: CVE-2026-19835

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-14T17:30:12Z

Weaknesses
  • CWE-266

    Incorrect Privilege Assignment

  • CWE-284

    Improper Access Control