What is CVE-2026-19996?
CVE-2026-19996 is a vulnerability in Webkul Bagisto up to version 2.4.4, affecting the Backend Customer Behavior Data endpoint at /admin/customers. It involves improper privilege management via manipulation of the ID argument, allowing remote exploitation. Administrators should apply security patches promptly.
Azərbaycanca: CVE-2026-19996, Webkul Bagisto 2.4.4-ə qədər olan versiyalarda, Backend Müştəri Davranış Məlumatı endpointində tapılan bir zəiflikdir. Bu, `/admin/customers` faylındakı ID parametrinin manipulyasiyası nəticəsində səlahiyyətlərin düzgün idarə edilməməsinə (improper privilege management) səbəb olur. Uzaqdan istismar mümkündür, ona görə də sistem administratorları dərhal təhlükəsizlik yamalarını tətbiq etməlidirlər.
Related CVEs
link basis: same weakness class CWE-269
FAQ2
Which versions of Webkul Bagisto are affected by CVE-2026-19996?
This vulnerability affects Webkul Bagisto up to version 2.4.4.
Which endpoint is exploited in CVE-2026-19996?
The exploitation occurs via manipulation of the ID argument at the /admin/customers endpoint.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.