


Perceptive Security
SOC/SIEM Consultancy

Shopper is a Headless e-commerce Admin Panel. Prior to 2.8.0, Multiple Filament actions on the admin Order detail and Order shipments table were callable by an …
Published:
28 May 2026 at 22:00:00
Alert date:
29 May 2026 at 21:09:42
Source:
nvd.nist.gov
Web Technologies, Enterprise Applications
A privilege escalation vulnerability in Shopper headless e-commerce admin panel prior to version 2.8.0 allows authenticated low-privilege users to perform unauthorized order management actions. Users with read-only permissions could execute critical order operations including payment capture, order cancellation, and status modifications. The vulnerability affects both order detail actions and shipment table operations, potentially allowing unauthorized real-world payment processing. This represents a significant authorization bypass that could lead to financial fraud and order manipulation.
Technical details
Mitigation steps:
Affected products:
Shopper
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-47740
https://github.com/shopperlabs/shopper/pull/511
https://github.com/shopperlabs/shopper/security/advisories/GHSA-f946-9qp6-vgch
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
