Description
A vulnerability was detected in Webkul Bagisto up to 2.4.4. Impacted is an unknown function of the file /customer/account/rma/store. The manipulation of the argument rma_qty/resolution_type/rma_reason_id results in enforcement of behavioral workflow. The attack may be performed from remote. The exploit is now public and may be used. The vendor confirms: "The reported issues were already identified through our internal security assessment process prior to this notification and are being handled through our established internal security and development lifecycle. Some of these items have already been addressed, while the remaining items are planned for resolution in upcoming product releases."
Published: 2026-08-17
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A flaw was found in Webkul Bagisto, affecting versions up to 2.4.4, where by manipulating the rma_qty, resolution_type, or rma_reason_id parameters in the /customer/account/rma/store request an attacker can force the application to follow an unintended behavioral workflow. The vulnerability is described as user‑controlled behavior enforcement and is known to be exploitable remotely. The weakness falls under CWE‑840, indicating insecure default or hardcoded settings, and CWE‑841, pointing to excessive permissions or overly permissive access controls. Without additional vendor data it is unclear what specific actions an attacker can perform, but the described intent suggests unauthorized operational behavior or elevated capabilities within the application.

Affected Systems

The affected product is Webkul Bagisto. All installations of version 2.4.4 or earlier that expose the /customer/account/rma/store endpoint are susceptible. The vendor states that some of the identified issues have been addressed and remaining ones are slated for future releases, meaning that systems running the latest version may no longer be vulnerable.

Risk and Exploitability

The CVSS score of 5.3 places this vulnerability in the medium severity range. The EPSS score is not available, and it is not listed in the CISA KEV catalog, but the public disclosure and the statement that the exploit is now public indicate that attackers could reason it is worthwhile to target vulnerable instances. The attack vector is remote: an attacker only needs to craft a web request containing the vulnerable parameters. No special conditions are noted, so the exploitability appears straightforward for an attacker with network or internet exposure to the target store.

Generated by OpenCVE AI on August 18, 2026 at 01:51 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the vendor’s patch for Bagisto 2.4.5 or newer once the fix is available. This is the principal remedy as the vendor indicates that some issues are already resolved in upcoming releases.
  • If an upgrade is not immediately possible, restrict access to the /customer/account/rma/store endpoint using web‑application firewall rules or HTTP authentication so that only trusted users can invoke that path.
  • Implement server‑side validation or sanitization for the rma_qty, resolution_type, and rma_reason_id parameters to ensure that only legitimate values can trigger workflow enforcement.

Generated by OpenCVE AI on August 18, 2026 at 01:51 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 19 Aug 2026 02:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 18 Aug 2026 00:00:00 +0000

Type Values Removed Values Added
Description A vulnerability was detected in Webkul Bagisto up to 2.4.4. Impacted is an unknown function of the file /customer/account/rma/store. The manipulation of the argument rma_qty/resolution_type/rma_reason_id results in enforcement of behavioral workflow. The attack may be performed from remote. The exploit is now public and may be used. The vendor confirms: "The reported issues were already identified through our internal security assessment process prior to this notification and are being handled through our established internal security and development lifecycle. Some of these items have already been addressed, while the remaining items are planned for resolution in upcoming product releases."
Title Webkul Bagisto store behavioral workflow
First Time appeared Webkul
Webkul bagisto
Weaknesses CWE-840
CWE-841
CPEs cpe:2.3:a:webkul:bagisto:*:*:*:*:*:*:*:*
Vendors & Products Webkul
Webkul bagisto
References
Metrics cvssV2_0

{'score': 4, 'vector': 'AV:N/AC:L/Au:S/C:N/I:P/A:N/E:POC/RL:ND/RC:UR'}

cvssV3_0

{'score': 4.3, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N/E:P/RL:X/RC:R'}

cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N/E:P/RL:X/RC:R'}

cvssV4_0

{'score': 5.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:P'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-08-18T13:31:55.519Z

Reserved: 2026-08-17T16:16:23.536Z

Link: CVE-2026-75081

cve-icon Vulnrichment

Updated: 2026-08-18T13:31:51.742Z

cve-icon NVD

Status : Deferred

Published: 2026-08-18T00:16:53.710

Modified: 2026-08-20T12:48:10.287

Link: CVE-2026-75081

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-18T02:00:05Z

Weaknesses