Skip to content
archivevulnerability · 11 Sep 2026 · 20:47 UTC

GHSA-243p-f3cv-c5wh: Shopper: Authorization bypass in Filament bulk actions allows browse-only staff to mass-delete attributes/tags

VULNCVE-2026-56827source · GTH
HIGHHigh-risk vulnerability — CVSS 8.1

last 60 dispatches · spectrum

## Summary Five Filament `groupedBulkActions` blocks across the Shopper admin Livewire pages omit the `->authorize(...)` permission gate, while their per-record sibling actions (and other Shopper Index pages such as `Pages/Settings/Currencies.php`, `Pages/Reviews/Index.php`, `Pages/Collection/Index.php`, and `Pages/Discount/Index.php`) correctly chain `->authorize(...)`. …

grounded ✓primary source ↗
Early access

Get the next one first.

Early access opens the actor API and MCP server first, plus alerts when an adversary you follow lands on the wire. One email when it's ready. Nothing else, ever.

bot-protected