Privilege Escalation Vulnerability in Webkul Bagisto by Webkul
CVE-2026-79411

8.8HIGH

Key Information:

Vendor

Webkul

Vendor
CVE Published:
15 September 2026

What is CVE-2026-79411?

The Webkul Bagisto platform has a significant vulnerability in its admin user-management component, where an authenticated backend user with minimal permissions can escalate their privileges to that of a full administrator. This flaw arises from the user-update endpoint failing to adequately validate the permissions of the requesting user, enabling them to assign themselves an Administrator role. Consequently, this low-privileged user can access critical functionalities, such as store configurations and sensitive customer information, thereby posing a serious threat to the integrity of the system.

References

CVSS V3.1

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.