What is CVE-2026-19997?
CVE-2026-19997 is an authorization bypass vulnerability discovered in Webkul Bagisto up to version 2.4.4, affecting the Backend Sales RMA Endpoint component. It allows remote attackers to perform unauthorized manipulation through the `/admin/sales/rma/requests` file. Users are advised to immediately update Bagisto to the latest patched version.
Azərbaycanca: CVE-2026-19997 Webkul Bagisto-nun 2.4.4 versiyasına qədər olan versiyalarında Backend Sales RMA Endpoint komponentində aşkar edilmiş avtorizasiya bypass zəifliyidir. Bu qüsur uzaqdan hücumçuya `/admin/sales/rma/requests` faylına icazəsiz giriş imkanı verir. İstifadəçilərə dərhal Bagisto versiyasını ən son təhlükəsizlik yeniləməsinə yüksəltmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-862; shared vendor: Webkul
FAQ2
Which versions of Webkul Bagisto are affected by CVE-2026-19997?
CVE-2026-19997 affects Webkul Bagisto up to version 2.4.4.
Which file can a remote attacker gain unauthorized access to via this authorization bypass vulnerability?
A remote attacker can gain unauthorized access to the `/admin/sales/rma/requests` file.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.