Headless E-commerce Admin Panel Vulnerability in Shopper by Shopper Labs
CVE-2026-56825
8.1HIGH
What is CVE-2026-56825?
The Shopper Headless e-commerce Admin Panel has a significant vulnerability that allows an authenticated staff user, possessing only browsing permissions, to exploit the functionality related to collection deletion. Specifically, prior to version 2.9.2, the system did not enforce adequate authorization when executing delete actions on collections. An attacker could invoke Livewire's removal actions with manipulated identifiers, potentially detaching products from collections or even emptying them entirely. This could lead to disruptions in catalog displays and promotional activities linked to affected collections, undermining the integrity of the e-commerce platform.
Affected Version(s)
shopper < 2.9.2
