Description
Shopper is a Headless e-commerce Admin Panel. Prior to 2.9.2, packages/admin/src/Livewire/Components/Products/VariantStock.php exposes stockAction() without edit_product_variants authorization and leaves public $variant client mutable because it lacks the Livewire Locked attribute. Any authenticated admin-panel user, including staff with only browse_products, can select an arbitrary product variant and inventory location through component state, then submit a positive or negative quantity adjustment. This permits browse-only staff to inflate stock, reduce stock, or force out-of-stock states for variants outside the current page. This issue is fixed in version 2.9.2.
Published: 2026-09-15
Score: 8.1 High
EPSS: < 1% Very Low
KEV: No
Impact: Modify inventory integrity
Action: Apply Patch
AI Analysis

Impact

An authenticated admin‑panel user can adjust inventory levels for any product variant without the required edit_product_variants authorization. The VariantStock component exposes the stockAction method without access control and the $variant property is not locked, allowing the page to modify it. This means staff with only browse_products permission can inflate stock, reduce stock, or force out‑of‑stock states for variants that are not visible on the current page. The weakness is a Broken Access Control flaw (CWE‑862), resulting in integrity violations and business impact through inaccurate inventory counts.

Affected Systems

Shopper Labs’ Shopper e‑commerce admin panel, versions earlier than 2.9.2. The vulnerability was fixed in release 2.9.2.

Risk and Exploitability

With a CVSS score of 8.1 the vulnerability is considered high severity. The EPSS score is < 1%, indicating a very low exploitation probability, and it is not listed in CISA KEV. The vulnerability can be exploited by any authenticated admin user with Browse‑Products permissions within the admin interface. An attacker can irregularly increase or decrease stock levels, leading to false inventory availability and associated financial loss.

Generated by OpenCVE AI on September 20, 2026 at 14:38 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade Shopper to version 2.9.2 or later
  • Ensure that stock updates require edit_product_variants authorization and that the VariantStock component’s properties are appropriately locked
  • Restrict staff with Browse‑Products permission from accessing inventory management interfaces

Generated by OpenCVE AI on September 20, 2026 at 14:38 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Github GHSA Github GHSA GHSA-g3f9-g5vj-p62f Shopper: Unauthorized inventory stock manipulation via unlocked variant property in VariantStock component
History

Tue, 15 Sep 2026 19:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 15 Sep 2026 19:00:00 +0000

Type Values Removed Values Added
First Time appeared Shopperlabs
Shopperlabs shopper
Vendors & Products Shopperlabs
Shopperlabs shopper

Tue, 15 Sep 2026 17:45:00 +0000

Type Values Removed Values Added
Description Shopper is a Headless e-commerce Admin Panel. Prior to 2.9.2, packages/admin/src/Livewire/Components/Products/VariantStock.php exposes stockAction() without edit_product_variants authorization and leaves public $variant client mutable because it lacks the Livewire Locked attribute. Any authenticated admin-panel user, including staff with only browse_products, can select an arbitrary product variant and inventory location through component state, then submit a positive or negative quantity adjustment. This permits browse-only staff to inflate stock, reduce stock, or force out-of-stock states for variants outside the current page. This issue is fixed in version 2.9.2.
Title Shopper: Unauthorized inventory stock manipulation via unlocked variant property in VariantStock component
Weaknesses CWE-862
References
Metrics cvssV3_1

{'score': 8.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H'}


Subscriptions

Shopperlabs Shopper
cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-09-15T19:04:52.685Z

Reserved: 2026-06-23T14:55:09.117Z

Link: CVE-2026-56829

cve-icon Vulnrichment

Updated: 2026-09-15T19:04:39.903Z

cve-icon NVD

Status : Deferred

Published: 2026-09-15T18:17:24.957

Modified: 2026-09-30T17:51:56.193

Link: CVE-2026-56829

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T14:45:06Z

Weaknesses