Discount Calculation Flaw in Shopper E-commerce Admin Panel
CVE-2026-56831

6.5MEDIUM

Key Information:

Status
Vendor
CVE Published:
15 September 2026

What is CVE-2026-56831?

The Shopper e-commerce Admin Panel contains a vulnerability in its /cpanel/discounts administrative interface that improperly handles negative fixed_amount discount values prior to version 2.9.0. This flaw allows for negative discounts to be stored and processed without validation, leading to incorrect pricing. When such discounts are applied, they erroneously increase the total order amount instead of reducing it. While the vulnerability does not present a direct customer-facing exploitation pathway, it poses risks related to inaccurate pricing and fails to maintain financial data integrity. This issue has been resolved in version 2.9.0.

Affected Version(s)

shopper < 2.9.0

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.