Shopper: Authorization bypass and RBAC privilege escalation in team settings
Published May 29, 2026
9.9
CRITICALCVSS 3.1
EPSS 0.42%
Description
Shopper is a Headless e-commerce Admin Panel. Prior to 2.8.0, two distinct authorization defects in the team settings allowed any authenticated panel user to take over the RBAC system. Settings/Team/Index had no mount() authorization. Any authenticated user could load the page and use its public actions to create new roles and delete other users, including administrators. Settings/Team/RolePermission gated its write actions on the read-only view_users permission. Any user holding view_users could grant themselves or any other user arbitrary permissions, including manage_users and edit_orders, effectively escalating to full panel administrator from a read-only account. Combined, these two defects allow a low-privilege authenticated user to obtain administrator privileges and remove the legitimate administrators from the panel. This vulnerability is fixed in 2.8.0.
Affected products
-
Affected
- < 2.8.0
Default status is the baseline for the product. Each version can override it (patched versions can be marked unaffected).
| Vendor | Product | Default status | Versions |
|---|---|---|---|
| Shopperlabs | Shopper | unknown | Affected
|
No data.
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
References (5)
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-33407 Advisory
- https://github.com/advisories/GHSA-c3qp-2ggw-xjg7 Advisory
- https://github.com/shopperlabs/shopper/pull/511
- https://github.com/shopperlabs/shopper/security/advisories/GHSA-c3qp-2ggw-xjg7 x_refsource_CONFIRM
- https://nvd.nist.gov/vuln/detail/CVE-2026-47744
Change history (0)
No recorded changes yet.
CVE.org / MITRE
CISA Vulnrichment
Red Hat
No data
GitHub