Public Access Route Vulnerability in EverShop Affects Customer Accounts
CVE-2026-72843

9.3CRITICAL

Key Information:

Status
Vendor
CVE Published:
20 August 2026

What is CVE-2026-72843?

A vulnerability in EverShop allows unauthenticated users to overwrite customer account details due to a public access route in the customer update API. This flaw permits attackers to manipulate customer records by using customer UUIDs exposed through various channels, thereby compromising account security. Without adequate ownership validation in place, an attacker can overwrite sensitive information such as email addresses and passwords, potentially locking legitimate users out of their accounts. Affected users are encouraged to upgrade to version 2.2.1, which addresses this issue by restricting access to authenticated users.

Affected Version(s)

evershop 0 < 2.2.1

evershop 2.2.1

References

CVSS V4

Score:
9.3
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

geo-chen
.