What is CVE-2026-19834?
An authorization bypass vulnerability was found in Webkul Bagisto up to version 2.4.4, affecting an unknown function in the /admin/customers/login-as-customer/ file via manipulation of the ID argument within the Admin Customer Impersonation Feature. This allows remote attacks, potentially granting unauthorized access. Users are advised to update to the latest version immediately and review access controls.
Azərbaycanca: Webkul Bagisto 2.4.4-ə qədər versiyalarında, /admin/customers/login-as-customer/ faylındakı ID arqumenti manipulyasiya edilərək Admin Customer Impersonation funksiyasında avtorizasiya bypass zəifliyi aşkar edilib. Bu, uzaqdan istismara imkan verir, təsirlənmiş sistemlərdə icazəsiz giriş riski yaradır. İstifadəçilərə dərhal ən son versiyaya yeniləmə və giriş nəzarətini yoxlamaq tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-284; shared vendor: Webkul
FAQ2
Which versions of Webkul Bagisto are affected by CVE-2026-19834?
This authorization bypass vulnerability affects Webkul Bagisto up to version 2.4.4.
What measures should be taken to protect against CVE-2026-19834?
Users are advised to update to the latest version immediately and review access controls.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.