Review reviewHigh
CVE-2026-59536
CoCart Headless CoCart – Headless ecommerce
Unauthenticated Broken Access Control in CoCart – Headless ecommerce <= 4.8.4 versions.
- CVSS
- 7.5
- EPSS
- - - percentile
- CISA KEV
- Not listed
- Published
- 2026.07.28
Unauthenticated Broken Access Control in CoCart – Headless ecommerce <= 4.8.4 versions.
The CVSS severity warrants an early asset and exposure review.
Unauthenticated Broken Access Control in CoCart – Headless ecommerce <= 4.8.4 versions.
Confirm exposure before applying a vendor-supported change.
Confirm that CoCart Headless CoCart – Headless ecommerce and an affected version are present.
Combine exploitation signals with asset exposure and business criticality.
Follow the vendor advisory or supported update path and preserve rollback options.
Recheck the version, service health, access paths, and relevant logs.