CVE-2026-56829
Shopper is a Headless e-commerce Admin Panel. Prior to 2.9.2, packages/admin/src/Livewire/Components/Products/VariantStock.php exposes stockAction() without edit_product_variants authorization and leaves public $variant client mutable because it lacks the Livewire Locked attribute. Any authenticated admin-panel user, including staff with only browse_products, can select an arbitrary product variant and inventory location through component state, then submit a positive or negative quantity adjustment. This permits browse-only staff to inflate stock, reduce stock, or force out-of-stock states for variants outside the current page. This issue is fixed in version 2.9.2.
Not on KEV
Not in CISA's Known Exploited Vulnerabilities catalogue as of the last daily pull. Absence is not proof of safety.
0%
Chance of exploitation in the next 30 days, 40th percentile of all CVEs. A forecast; KEV outranks it.
8.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H
—
No exposure census on this CVE's dispatches.
- nvd.nist.gov ↗
- first.org · EPSS ↗
- github.com/shopperlabs/shopper/commit/bf72e2753e21296184596d507336c7d65ecd46ff ↗
- github.com/shopperlabs/shopper/pull/570 ↗
- github.com/shopperlabs/shopper/releases/tag/v2.9.2 ↗
- github.com/shopperlabs/shopper/security/advisories/GHSA-g3f9-g5vj-p62f ↗
- github.com/shopperlabs/shopper/security/advisories/GHSA-g3f9-g5vj-p62f ↗
Watch this one?
Early access opens alerts first — one email when a CVE you follow lands on KEV or an adversary you follow lands on the wire. Nothing else, ever.