Authorization Flaw in Shopper E-commerce Admin Panel by Shopper Labs
CVE-2026-56829
8.1HIGH
What is CVE-2026-56829?
The Shopper E-commerce Admin Panel suffers from an authorization oversight in its stock management functionality. Specifically, prior to version 2.9.2, the 'stockAction()' method within the Livewire Components allows any authenticated user—regardless of their access level—to alter product inventory without appropriate permissions. This flaw permits even browse-only users to manipulate stock levels, leading to potential inventory inflation, depletion, or incorrect out-of-stock states for product variants outside their current view. This vulnerability has been addressed in version 2.9.2, which restricts access to authorized personnel only.
Affected Version(s)
shopper < 2.9.2
