Public Access Route Vulnerability in EverShop Affects Customer Accounts
CVE-2026-72843
9.3CRITICAL
What is CVE-2026-72843?
A vulnerability in EverShop allows unauthenticated users to overwrite customer account details due to a public access route in the customer update API. This flaw permits attackers to manipulate customer records by using customer UUIDs exposed through various channels, thereby compromising account security. Without adequate ownership validation in place, an attacker can overwrite sensitive information such as email addresses and passwords, potentially locking legitimate users out of their accounts. Affected users are encouraged to upgrade to version 2.2.1, which addresses this issue by restricting access to authenticated users.
Affected Version(s)
evershop 0 < 2.2.1
evershop 2.2.1
