Description
A vulnerability has been found in Webkul Bagisto up to 2.4.4. Affected by this vulnerability is an unknown functionality of the file /customer/account/rma/update-status of the component RMA State Validation. The manipulation leads to enforcement of behavioral workflow. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The vendor confirms: "The reported issues were already identified through our internal security assessment process prior to this notification and are being handled through our established internal security and development lifecycle. Some of these items have already been addressed, while the remaining items are planned for resolution in upcoming product releases."
Published: 2026-08-17
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A flaw exists in the RMA State Validation component of Webkul Bagisto that allows manipulation of the /customer/account/rma/update-status endpoint, thereby forcing an unintended behavioral workflow. The weakness involves deserialization of untrusted data (CWE-840) and failure to restrict access to the endpoint (CWE-841), making it possible for an attacker to change the status of a Return Merchandise Authorization without consent.

Affected Systems

Webkul Bagisto versions up to 2.4.4 are impacted. No other vendors or products are listed as affected.

Risk and Exploitability

The CVSS score of 5.3 indicates a moderate severity, and although no EPSS score is available, the vulnerability has been publicly disclosed and can be triggered remotely. The vendor has acknowledged the issue and is planning a fix in forthcoming releases, but the vulnerability is not yet listed in the CISA KEV catalog. In the absence of proof of exploitation, the risk remains moderate, though any successful call to the vulnerable endpoint could upset inventory and financial records.

Generated by OpenCVE AI on August 17, 2026 at 07:23 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrading to the latest Bagisto release that includes the Fix for the RMA status update endpoint (2.4.5 or newer).
  • Applying strict role‑based access control so that only authorized staff can invoke /customer/account/rma/update-status.
  • Validating and sanitizing all input parameters to the RMA state transition logic to prevent unintended state changes.

Generated by OpenCVE AI on August 17, 2026 at 07:23 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 19 Aug 2026 02:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 17 Aug 2026 06:15:00 +0000

Type Values Removed Values Added
Description A vulnerability has been found in Webkul Bagisto up to 2.4.4. Affected by this vulnerability is an unknown functionality of the file /customer/account/rma/update-status of the component RMA State Validation. The manipulation leads to enforcement of behavioral workflow. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The vendor confirms: "The reported issues were already identified through our internal security assessment process prior to this notification and are being handled through our established internal security and development lifecycle. Some of these items have already been addressed, while the remaining items are planned for resolution in upcoming product releases."
Title Webkul Bagisto RMA State Validation update-status behavioral workflow
First Time appeared Webkul
Webkul bagisto
Weaknesses CWE-840
CWE-841
CPEs cpe:2.3:a:webkul:bagisto:*:*:*:*:*:*:*:*
Vendors & Products Webkul
Webkul bagisto
References
Metrics cvssV2_0

{'score': 4, 'vector': 'AV:N/AC:L/Au:S/C:N/I:P/A:N/E:POC/RL:ND/RC:UR'}

cvssV3_0

{'score': 4.3, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N/E:P/RL:X/RC:R'}

cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N/E:P/RL:X/RC:R'}

cvssV4_0

{'score': 5.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:P'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-08-18T13:37:24.496Z

Reserved: 2026-08-16T18:05:09.383Z

Link: CVE-2026-19993

cve-icon Vulnrichment

Updated: 2026-08-18T13:24:17.058Z

cve-icon NVD

Status : Deferred

Published: 2026-08-17T06:17:39.957

Modified: 2026-08-20T12:48:10.287

Link: CVE-2026-19993

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-17T08:15:17Z

Weaknesses