Privilege Escalation Vulnerability in Webkul Bagisto by Webkul
CVE-2026-79411
8.8HIGH
What is CVE-2026-79411?
The Webkul Bagisto platform has a significant vulnerability in its admin user-management component, where an authenticated backend user with minimal permissions can escalate their privileges to that of a full administrator. This flaw arises from the user-update endpoint failing to adequately validate the permissions of the requesting user, enabling them to assign themselves an Administrator role. Consequently, this low-privileged user can access critical functionalities, such as store configurations and sensitive customer information, thereby posing a serious threat to the integrity of the system.
