What is CVE-2026-50986?
CVE-2026-50986 is a Cross Site Request Forgery (CSRF) vulnerability in the PrestaShop totadministrativemandate module before version 1.8.1. The payment validation controller lacks a CSRF token, allowing an attacker to confirm an order in an awaiting status by hijacking a link. Upgrading the module to version 1.8.1 or later is recommended.
Azərbaycanca: CVE-2026-50986, PrestaShop-un totadministrativemandate modulunda 1.8.1 versiyasından əvvəlki bütün versiyalarda CSRF (Cross Site Request Forgery) zəifliyidir. Ödəniş təsdiqləmə controllerində CSRF token olmaması səbəbindən, təcavüzkar linki ələ keçirərək gözləmədə olan sifarişi təsdiqləyə bilər. Modulu 1.8.1 və ya daha son versiyaya yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-352
FAQ2
How to protect against CVE-2026-50986?
By upgrading the totadministrativemandate module to version 1.8.1 or later.
What can an attacker do in CVE-2026-50986?
By exploiting the lack of a CSRF token in the payment validation controller, an attacker can hijack a link to confirm an order in an awaiting status.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.