


Perceptive Security
SOC/SIEM Consultancy

Shopper is a Headless e-commerce Admin Panel. Prior to 2.8.0, two distinct authorization defects in the team settings allowed any authenticated panel user to ta…
Published:
28 mei 2026 om 22:00:00
Alert date:
29 mei 2026 om 20:03:36
Source:
nvd.nist.gov
Web Technologies, Identity & Access
Shopper headless e-commerce admin panel contains two critical authorization defects in team settings that allow authenticated users to take over the RBAC system. The vulnerabilities enable privilege escalation from low-privilege user to full administrator through missing authorization checks in Settings/Team/Index and improper permission gating in Settings/Team/RolePermission. Attackers can create roles, delete administrators, and grant arbitrary permissions. The vulnerabilities affect versions prior to 2.8.0 and have been patched in version 2.8.0.
Technical details
Mitigation steps:
Affected products:
Shopper
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-47744
https://github.com/shopperlabs/shopper/security/advisories/GHSA-c3qp-2ggw-xjg7
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
