Skip to content
archivevulnerability · 11 Sep 2026 · 21:28 UTC

GHSA-j328-xmgp-j4q3: Shopper: privilege escalation via improper Livewire admin component authorization

VULNCVE-2026-56828source · GTH
HIGHHigh-risk vulnerability — CVSS 8.8

last 60 dispatches · spectrum

## Summary Three Livewire admin components in `shopper/framework` (latest master at commit `fcd0c59`, released as v2.8.0) gate state-mutating actions on the read-only `view_users` permission. This is the same class as the issue Shopper fixed in v2.8.0 / PR #511 / [GHSA-f946-9qp6-vgch](https://github.com/shopperlabs/shopper/security/advisories/GHSA-f946-9qp6-vgch) — the PR moved most write actions from `view_users` to `access_setting`, but three were missed (one of them is a brand-new file added by the security commit itself). …

grounded ✓primary source ↗
Early access

Get the next one first.

Early access opens the actor API and MCP server first, plus alerts when an adversary you follow lands on the wire. One email when it's ready. Nothing else, ever.

bot-protected