Authorization Bypass Vulnerability in Webkul Bagisto Backend Reporting Endpoint
CVE-2026-19838
Key Information:
Badges
What is CVE-2026-19838?
A significant security issue has been identified in the Webkul Bagisto platform, specifically within the Backend Reporting Endpoint located at /admin/reporting/sales/. This vulnerability allows unauthorized users to bypass access controls, potentially leading to unauthorized data exposure and manipulation. The exploit is capable of remote execution, posing a critical risk to affected systems. Webkul has acknowledged the vulnerability, stating that it was discovered through their internal security assessments, with ongoing measures to address the issue in future releases.
Affected Version(s)
Bagisto 2.4.0
Bagisto 2.4.1
Bagisto 2.4.2
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved
