GDPR Consent Log Forgery in PrestaShop psgdpr
CVE-2026-92809
Key Information:
- Vendor
Prestashop
- Status
- Vendor
- CVE Published:
- 16 September 2026
Badges
What is CVE-2026-92809?
The PrestaShop psgdpr module versions up to 1.4.3 exhibit a vulnerability where the system fails to properly verify that GDPR consent log entries belong to the authenticated user. This flaw allows authenticated attackers to exploit the application by submitting arbitrary customer identifiers, resulting in the creation of fraudulent consent records for other users. This not only compromises the integrity of audit logs but also poses significant risks to data protection compliance and customer privacy.
Affected Version(s)
psgdpr 0 <= 1.4.3
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved
