Authorization Flaw in Shopper E-commerce Admin Panel Affects Bulk Actions
CVE-2026-56827

8.1HIGH

Key Information:

Status
Vendor
CVE Published:
15 September 2026

What is CVE-2026-56827?

The Shopper E-commerce Admin Panel has an authorization flaw in multiple Livewire pages prior to version 2.9.2, which allows browse-only staff users to perform bulk deletion of attributes or tags without proper authorization. This issue can potentially disrupt storefront catalog visibility by altering the visibility settings of attributes, brands, categories, and suppliers. Notably, individual record actions and authorization of comparison pages remain unaffected. Users are encouraged to update to the fixed version 2.9.2 to mitigate these risks.

Affected Version(s)

shopper < 2.9.2

References

CVSS V3.1

Score:
8.1
Severity:
HIGH
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.