PT-2026-73217 · Webkul · Bagisto

·

CVE-2026-19996

·

Published

2026-08-17

·

Updated

2026-08-17

CVSS v3.1

4.3

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions Webkul Bagisto versions prior to 2.4.5
Description Improper privilege management exists in the Backend Customer Behavior Data Endpoint within the /admin/customers file. A remote attacker can manipulate the ID argument to bypass intended access controls.
Recommendations Update to a version newer than 2.4.4. Restrict access to the /admin/customers endpoint to minimize the risk of exploitation.

Exploit

Fix

Incorrect Privilege Assignment

Improper Privilege Management

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-19996

Affected Products

Bagisto