


Perceptive Security
SOC/SIEM Consultancy

Shopper is a Headless e-commerce Admin Panel. Prior to 2.8.0, Multiple Filament actions on the admin Order detail and Order shipments table were callable by an …
Published:
28 May 2026 at 22:00:00
Alert date:
29 May 2026 at 20:03:36
Source:
nvd.nist.gov
Web Technologies, Enterprise Applications
CVE-2026-47740 affects Shopper, a headless e-commerce admin panel, prior to version 2.8.0. The vulnerability allows authenticated low-privilege users to perform order management actions without proper permissions. Users with read-only access could cancel orders, mark them as paid or complete, capture payments, and modify shipments. The capturePayment action could trigger actual payment service provider captures, resulting in real funds movement. This represents a critical privilege escalation that could lead to financial fraud and order manipulation.
Technical details
Mitigation steps:
Affected products:
Shopper
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-47740
https://github.com/shopperlabs/shopper/pull/511
https://github.com/shopperlabs/shopper/security/advisories/GHSA-f946-9qp6-vgch
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
