PT-2026-72034 · Webkul · Bagisto

·

CVE-2026-19834

·

Published

2026-08-14

·

Updated

2026-08-18

CVSS v2.0

5.8

Medium

VectorAV:N/AC:L/Au:M/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Webkul Bagisto versions prior to 2.4.5
Description An authorization bypass exists in the Admin Customer Impersonation Feature within the file /admin/customers/login-as-customer/. A remote attacker can exploit this by manipulating the ID argument, allowing them to bypass authorization controls.
Recommendations Update Webkul Bagisto to version 2.4.5 or later. As a temporary mitigation, restrict access to the /admin/customers/login-as-customer/ file.

Exploit

Fix

IDOR

Improper Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-19834

Affected Products

Bagisto