Description
An issue in Webkul Bagisto 2.4.9 allows a remote attacker to obtain sensitive information via the add-to-cart API and the downloadable fulfilment components.
Published: 2026-09-15
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Information Disclosure
Action: Patch
AI Analysis

Impact

An issue in Webkul Bagisto 2.4.9 enables a remote attacker to retrieve sensitive information by interacting with the add‑to‑cart API and the downloadable fulfilment components. The flaw permits disclosure of data that should be protected, potentially including product details, inventory levels, or other internal information. The vulnerability falls under CWE‑639 Information disclosure through system configuration.

Affected Systems

Webkul Bagisto version 2.4.9 is impacted.

Risk and Exploitability

The CVSS score of 6.5 indicates moderate severity. Because the exploit can be performed remotely via an application API request, an attacker with network access could potentially launch the attack without needing credentials. The EPSS score is < 1% and the vulnerability is not listed in the CISA KEV catalog. Based on the description, it is inferred that the attack vector is remote and that the exploit requires only sending crafted requests to the add‑to‑cart endpoint, making it fairly easy to execute.

Generated by OpenCVE AI on September 20, 2026 at 17:54 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the latest Bagisto patch (version 2.4.10 or later) to eliminate the disclosure flaw.
  • Restrict access to the add‑to‑cart API by firewall rules or application‑level authentication to limit who can invoke the endpoint.
  • Monitor API logs for unusual activity or repeated add‑to‑cart requests that may indicate exploitation attempts.

Generated by OpenCVE AI on September 20, 2026 at 17:54 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 20 Sep 2026 18:15:00 +0000

Type Values Removed Values Added
Title Information Disclosure via Add‑to‑Cart API in Webkul Bagisto

Thu, 17 Sep 2026 21:45:00 +0000

Type Values Removed Values Added
Title Information Disclosure via Add‑to‑Cart API in Webkul Bagisto 2.4.9

Wed, 16 Sep 2026 07:30:00 +0000

Type Values Removed Values Added
Title Information Disclosure via Add‑to‑Cart API in Webkul Bagisto 2.4.9

Tue, 15 Sep 2026 23:00:00 +0000

Type Values Removed Values Added
First Time appeared Webkul
Webkul bagisto
Vendors & Products Webkul
Webkul bagisto

Tue, 15 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 15 Sep 2026 19:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-639
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N'}


Tue, 15 Sep 2026 19:00:00 +0000

Type Values Removed Values Added
Description An issue in Webkul Bagisto 2.4.9 allows a remote attacker to obtain sensitive information via the add-to-cart API and the downloadable fulfilment components.
References

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2026-09-15T19:09:34.667Z

Reserved: 2026-08-25T00:00:00.000Z

Link: CVE-2026-79409

cve-icon Vulnrichment

Updated: 2026-09-15T19:09:24.959Z

cve-icon NVD

Status : Deferred

Published: 2026-09-15T19:17:39.737

Modified: 2026-09-22T20:00:03.713

Link: CVE-2026-79409

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T18:00:14Z

Weaknesses
  • CWE-639

    Authorization Bypass Through User-Controlled Key