Product Manipulation Vulnerability in Shopper E-commerce Admin Panel
CVE-2026-56830

6.5MEDIUM

Key Information:

Status
Vendor
CVE Published:
15 September 2026

What is CVE-2026-56830?

A vulnerability in the Shopper E-commerce Admin Panel allows authenticated staff users with browsing permissions to bypass authorization checks when replacing product images. Specifically, prior to version 2.9.2, the store() function in the Media component lacked the necessary edit_products authorization, permitting unauthorized changes to product thumbnails and galleries. This issue affects only those products whose edit pages have been previously accessed, limiting the potential for broader exploitation. The vulnerability has been addressed in the latest update, version 2.9.2.

Affected Version(s)

shopper < 2.9.2

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.