Description
A security flaw has been discovered in Webkul Bagisto up to 2.4.4. Affected by this issue is some unknown functionality of the file /admin/customers/view of the component Backend Customer Detail Feature. Performing a manipulation of the argument ID results in authorization bypass. The attack may be initiated remotely. The exploit has been released to the public and may be used for attacks. The vendor confirms: "The reported issues were already identified through our internal security assessment process prior to this notification and are being handled through our established internal security and development lifecycle. Some of these items have already been addressed, while the remaining items are planned for resolution in upcoming product releases."
Published: 2026-08-14
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A flaw in the admin customer detail view of Webkul Bagisto 2.4.4 and earlier allows an attacker to manipulate the customer ID parameter and view customer information without proper authentication. This results in an authorization bypass that can expose private customer data, with the underlying weakness reflected in CWE‑285 and CWE‑639.

Affected Systems

Webkul Bagisto versions up to 2.4.4 are affected. The vulnerability exists in the /admin/customers/view endpoint of the Backend Customer Detail Feature component.

Risk and Exploitability

The CVSS score of 5.3 indicates a moderate impact, and no EPSS score is available; however, the exploit has been released to the public and may be launched remotely. Attackers need only reach the admin endpoint—no additional elevated rights are required—and can manipulate the ID argument to bypass authentication. Based on the description, it is inferred that this access could serve as a foothold for more advanced attacks, but that inference is not directly stated in the official details. The vulnerability is not listed in CISA’s KEV catalog.

Generated by OpenCVE AI on August 14, 2026 at 16:50 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade to the latest Bagisto release that contains the fix for the authorization bypass vulnerability.
  • Re‑configure administrative ACLs to ensure that only authorized roles can access the /admin/customers/view endpoint.
  • Audit existing customer records for any exposure and rotate credentials if necessary.

Generated by OpenCVE AI on August 14, 2026 at 16:50 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 14 Aug 2026 15:45:00 +0000

Type Values Removed Values Added
Description A security flaw has been discovered in Webkul Bagisto up to 2.4.4. Affected by this issue is some unknown functionality of the file /admin/customers/view of the component Backend Customer Detail Feature. Performing a manipulation of the argument ID results in authorization bypass. The attack may be initiated remotely. The exploit has been released to the public and may be used for attacks. The vendor confirms: "The reported issues were already identified through our internal security assessment process prior to this notification and are being handled through our established internal security and development lifecycle. Some of these items have already been addressed, while the remaining items are planned for resolution in upcoming product releases."
Title Webkul Bagisto Backend Customer Detail Feature view authorization
First Time appeared Webkul
Webkul bagisto
Weaknesses CWE-285
CWE-639
CPEs cpe:2.3:a:webkul:bagisto:*:*:*:*:*:*:*:*
Vendors & Products Webkul
Webkul bagisto
References
Metrics cvssV2_0

{'score': 4, 'vector': 'AV:N/AC:L/Au:S/C:P/I:N/A:N/E:POC/RL:ND/RC:UR'}

cvssV3_0

{'score': 4.3, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N/E:P/RL:X/RC:R'}

cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N/E:P/RL:X/RC:R'}

cvssV4_0

{'score': 5.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:P'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-08-18T13:38:58.875Z

Reserved: 2026-08-14T07:44:22.437Z

Link: CVE-2026-19836

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Deferred

Published: 2026-08-14T16:16:54.743

Modified: 2026-08-18T14:16:58.317

Link: CVE-2026-19836

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-14T17:00:15Z

Weaknesses
  • CWE-285

    Improper Authorization

  • CWE-639

    Authorization Bypass Through User-Controlled Key