CVE-2026-47744
shopperlabs shopper
Shopper is a Headless e-commerce Admin Panel. Prior to 2.8.0, two distinct authorization defects in the team settings allowed any authenticated panel user to take over the RBAC system. Settings/Team/Index had no mount() authorization. Any authenticated user could load the page and use its public actions to create new roles and delete other users, including administrators. Settings/Team/RolePermission gated its write actions on the read-only view_users permission. Any user holding view_users could grant themselves or any other user arbitrary permissions, including manage_users and edit_order...
- CVSS
- 9.9
- EPSS
- 0.32% 24.5% percentile
- CISA KEV
- Not listed
- Published
- 2026.05.30