Description
Incorrect privilege assignment in the admin user-management component of Webkul Bagisto 2.4.9 allows an authenticated backend user holding only the settings.users.edit permission to escalate to full administrator. The user-update endpoint (route admin.settings.users.update, UserController::update()) does not verify that the actor is permitted to grant the requested role, does not prevent a user from changing their own role, and does not restrict assignment to roles whose permission set is a subset of the actor's own. By submitting a request that sets role_id to the Administrator role for their own account, a low-privileged administrator gains every admin-panel capability, including store configuration, payment gateway credentials, and customer PII.
Published: 2026-09-15
Score: 8.8 High
EPSS: < 1% Very Low
KEV: No
Impact: Privilege Escalation to Administrator
Action: Apply Patch
AI Analysis

Impact

The bug in Webkul Bagisto 2.4.9 allows a backend user who holds only the settings.users.edit permission to gain full administrator privileges. The user‑update endpoint does not validate that the actor is authorized to grant a requested role, does not prevent users from assigning a role to themselves, and does not enforce that the requested role’s permission set is a subset of the actor’s own. By sending a request that sets role_id to the Administrator role for their own account, the attacker can elevate privileges and gain access to all admin‑panel functions, including store configuration, payment gateway credentials, and customer personal data.

Affected Systems

Webkul Bagisto 2.4.9 installations with the admin user‑management component enabled. Merchants who have not applied the official patch or upgraded to a version in which the issue is fixed are affected. The vulnerability is specific to this version; newer releases contain the fix.

Risk and Exploitability

The vulnerability carries a CVSS score of 8.8, classifying it as high severity. EPSS indicates less than 1% exploitation probability, and the flaw is not listed in CISA KEV. Nonetheless, any authenticated user with the minimal settings.users.edit permission can craft a request to the /admin/settings/users/update route to change their own role, granting full administrator rights. The lack of authorization checks makes the attack straightforward for anyone with access to the backend, creating a serious risk for data confidentiality, integrity, and availability if exploited.

Generated by OpenCVE AI on September 20, 2026 at 17:53 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the official vendor patch or upgrade Bagisto to the latest version that resolves the privilege assignment flaw.
  • Temporarily revoke or restrict the settings.users.edit permission from all users until the patch is applied.
  • Audit administrative logs for unauthorized role changes and conduct regular user‑account reviews to ensure no unexpected permission escalations have occurred.

Generated by OpenCVE AI on September 20, 2026 at 17:53 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 20 Sep 2026 18:15:00 +0000

Type Values Removed Values Added
Title Privilege Escalation via Incorrect Role Assignment in Webkul Bagisto 2.4.9

Thu, 17 Sep 2026 21:45:00 +0000

Type Values Removed Values Added
Title Privilege Escalation via Role Assignment in Bagisto 2.4.9
Weaknesses CWE-285

Wed, 16 Sep 2026 17:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-269
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 16 Sep 2026 07:30:00 +0000

Type Values Removed Values Added
Title Privilege Escalation via Role Assignment in Bagisto 2.4.9
Weaknesses CWE-285

Tue, 15 Sep 2026 23:00:00 +0000

Type Values Removed Values Added
First Time appeared Webkul
Webkul bagisto
Vendors & Products Webkul
Webkul bagisto

Tue, 15 Sep 2026 19:00:00 +0000

Type Values Removed Values Added
Description Incorrect privilege assignment in the admin user-management component of Webkul Bagisto 2.4.9 allows an authenticated backend user holding only the settings.users.edit permission to escalate to full administrator. The user-update endpoint (route admin.settings.users.update, UserController::update()) does not verify that the actor is permitted to grant the requested role, does not prevent a user from changing their own role, and does not restrict assignment to roles whose permission set is a subset of the actor's own. By submitting a request that sets role_id to the Administrator role for their own account, a low-privileged administrator gains every admin-panel capability, including store configuration, payment gateway credentials, and customer PII.
References

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2026-09-16T16:45:14.393Z

Reserved: 2026-08-25T00:00:00.000Z

Link: CVE-2026-79411

cve-icon Vulnrichment

Updated: 2026-09-16T16:45:05.455Z

cve-icon NVD

Status : Deferred

Published: 2026-09-15T19:17:40.093

Modified: 2026-09-22T20:00:03.713

Link: CVE-2026-79411

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T18:00:14Z

Weaknesses
  • CWE-269

    Improper Privilege Management