Webkul · Bagisto · CVE-2026-19837
**Name of the Vulnerable Software and Affected Versions**
Webkul Bagisto versions prior to 2.4.5
**Description**
A weakness in the Customer Search component, specifically within the `/admin/customers/search` endpoint, allows for remote information disclosure. This occurs when the `Query` argument is manipulated, enabling an attacker to access sensitive data.
**Recommendations**
Update Webkul Bagisto to version 2.4.5 or later.
As a temporary mitigation, restrict access to the `/admin/customers/search` endpoint.