Cross Site Request Forgery Vulnerability in PrestaShop Payment Module
CVE-2026-50986

8.8HIGH

Key Information:

Vendor

PrestaShop

Vendor
CVE Published:
31 July 2026

What is CVE-2026-50986?

The PrestaShop module named totadministrativemandate, versions prior to 1.8.1, is susceptible to Cross Site Request Forgery (CSRF) attacks. This vulnerability occurs because the payment validation controller fails to implement a CSRF token, allowing unauthorized users to manipulate order confirmations. By hijacking specific links, attackers can confirm orders that are in an awaiting status, potentially leading to financial loss and a breach of customer trust.

References

CVSS V3.1

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.