What is CVE-2026-19994?
This CVE describes an authorization bypass vulnerability found in Webkul Bagisto versions up to 2.4.4 within the Configuration Management component. The flaw exists due to manipulation of the 'action' argument in the '/admin/configuration/cache-management/execute' file. Users are advised to immediately upgrade to the latest patched version.
Azərbaycanca: Bu CVE, Webkul Bagisto platformunun 2.4.4-ə qədər olan versiyalarında Konfiqurasiya İdarəetməsi bölməsində aşkarlanmış avtorizasiya bypass zəifliyidir. Zəiflik "/admin/configuration/cache-management/execute" faylındakı "action" arqumentinin manipulyasiyası nəticəsində baş verir. İstifadəçilərə dərhal platformanı ən son versiyaya yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-863; shared vendor: Webkul
FAQ2
Which versions of Webkul Bagisto are affected by CVE-2026-19994?
This vulnerability affects Webkul Bagisto versions up to 2.4.4.
What action is recommended to mitigate CVE-2026-19994?
Users are advised to immediately upgrade to the latest patched version.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.