Authorization Bypass in CoreShop's OrderController Affects User Orders
CVE-2026-108696
5.3MEDIUM
What is CVE-2026-108696?
CoreShop versions up to 1.5.5 have a significant authorization bypass vulnerability within the OrderController. This flaw allows authenticated users to manipulate and act upon other users' orders by exploiting user-controlled identifiers. Attackers can confirm the receipt of orders not belonging to them by omitting certain required data in the OrderConfirm process or providing a different reshipId in the SendReship function, thus potentially overwriting sensitive return tracking information. Proper mitigation and updates are essential to safeguard customer data and maintain application integrity.
Affected Version(s)
CoreShop 0 <= 1.5.5
