What is CVE-2026-19836?
A critical authorization bypass vulnerability has been identified in Webkul Bagisto up to version 2.4.4, specifically within the backend customer detail feature. The flaw in the /admin/customers/view file allows attackers to manipulate the ID argument to gain unauthorized access. Immediate update to the latest patched version is strongly advised.
Azərbaycanca: Webkul Bagisto platformasının 2.4.4 versiyasına qədər olan versiyalarında müştəri idarəetmə panelində kritik bir identifikasiya yan keçmə (authorization bypass) zəifliyi aşkar edilib. Bu boşluq /admin/customers/view faylındakı ID arqumentinin manipulyasiyası ilə icazəsiz girişə imkan verir. Təcili olaraq platformanı ən son versiyaya yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-862; shared vendor: Webkul
FAQ2
Which versions of the Bagisto platform are affected by the CVE-2026-19836 authorization bypass vulnerability?
All versions of Webkul Bagisto up to version 2.4.4 are affected by this vulnerability.
How can an attacker gain unauthorized access using the CVE-2026-19836 vulnerability?
An attacker can gain unauthorized access to the backend customer detail feature by manipulating the ID argument in the /admin/customers/view file.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.