Headless E-commerce Admin Panel Vulnerability in Shopper by Shopper Labs
CVE-2026-56825

8.1HIGH

Key Information:

Status
Vendor
CVE Published:
15 September 2026

What is CVE-2026-56825?

The Shopper Headless e-commerce Admin Panel has a significant vulnerability that allows an authenticated staff user, possessing only browsing permissions, to exploit the functionality related to collection deletion. Specifically, prior to version 2.9.2, the system did not enforce adequate authorization when executing delete actions on collections. An attacker could invoke Livewire's removal actions with manipulated identifiers, potentially detaching products from collections or even emptying them entirely. This could lead to disruptions in catalog displays and promotional activities linked to affected collections, undermining the integrity of the e-commerce platform.

Affected Version(s)

shopper < 2.9.2

References

CVSS V3.1

Score:
8.1
Severity:
HIGH
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.