What is CVE-2026-75081?
CVE-2026-75081 is a vulnerability found in Webkul Bagisto up to version 2.4.4, impacting an unknown function in the `/customer/account/rma/store` file. Manipulation of the `rma_qty`, `resolution_type`, and `rma_reason_id` arguments leads to enforcement of behavioral workflow, potentially allowing remote attacks. Users should update to the latest patched version to mitigate this issue.
Azərbaycanca: CVE-2026-75081 zəifliyi Webkul Bagisto proqramının 2.4.4 versiyasına qədər olan versiyalarında aşkarlanıb. Bu, `/customer/account/rma/store` faylındakı naməlum funksiyaya təsir edir və `rma_qty`, `resolution_type`, `rma_reason_id` arqumentlərinin manipulyasiyası nəticəsində iş axını məntiqinin (enforcement of behavioral workflow) pozulmasına səbəb olur. Uzaqdan həyata keçirilə bilən bu hücuma qarşı Webkul Bagisto-nu ən son versiyaya yeniləmək tövsiyə olunur.
Related CVEs
link basis: shared vendor: Webkul
FAQ2
Which versions of Webkul Bagisto are affected by CVE-2026-75081?
CVE-2026-75081 affects Webkul Bagisto up to version 2.4.4.
Which arguments are manipulated to exploit CVE-2026-75081?
The vulnerability arises from the manipulation of the `rma_qty`, `resolution_type`, and `rma_reason_id` arguments in the `/customer/account/rma/store` file.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.