Authorization Bypass Vulnerability in Webkul Bagisto Backend Customer Detail Feature
CVE-2026-19836
Key Information:
Badges
What is CVE-2026-19836?
A security vulnerability has been identified in Webkul Bagisto, specifically within the Backend Customer Detail Feature. The issue resides in the file /admin/customers/view, where manipulating the argument ID can lead to unauthorized access. This flaw allows attackers to remotely exploit the system. The vulnerabilities have been acknowledged by the vendor, which previously detected some of these security issues during their internal security assessments. They are actively addressing these vulnerabilities within their development timeline, with resolutions for some already in progress for upcoming product releases.
Affected Version(s)
Bagisto 2.4.0
Bagisto 2.4.1
Bagisto 2.4.2
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved
