CVE-2026-56829
published 2026-09-15CVE-2026-56829: Shopper is a Headless e-commerce Admin Panel. Prior to 2.9.2, packages/admin/src/Livewire/Components/Products/VariantStock.php exposes stockAction() without…
PriorityP349high8.1CVSS 3.1
AVNACLPRLUINSUCNIHAH
EPSS
0.47%
39.8th percentile
Shopper is a Headless e-commerce Admin Panel. Prior to 2.9.2, packages/admin/src/Livewire/Components/Products/VariantStock.php exposes stockAction() without edit_product_variants authorization and leaves public $variant client mutable because it lacks the Livewire Locked attribute. Any authenticated admin-panel user, including staff with only browse_products, can select an arbitrary product variant and inventory location through component state, then submit a positive or negative quantity adjustment. This permits browse-only staff to inflate stock, reduce stock, or force out-of-stock states for variants outside the current page. This issue is fixed in version 2.9.2.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| shopper | framework | >= 0 < 2.9.2 | 2.9.2 |
| shopperlabs | shopper | < 2.9.2 | 2.9.2 |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
Shopper VariantStock VariantStock.php stockAction variant privileges management
vuldb·2026-09-12
CVE-2026-56829 [LOW] Shopper VariantStock VariantStock.php stockAction variant privileges management
A vulnerability labeled as problematic has been found in Shopper. The impacted element is the function stockAction of the file packages/admin/src/Livewire/Components/Products/VariantStock.php of the component VariantStock. The manipulation of the argument variant results in improper privilege management.
This vulnerability is cataloged as CVE-2026-56829. The attack may be launched remotely. There is no exploit available.
GHSA
Shopper: Unauthorized inventory stock manipulation via unlocked variant property in VariantStock component
ghsa·2026-09-11
CVE-2026-56829 [HIGH] CWE-862 Shopper: Unauthorized inventory stock manipulation via unlocked variant property in VariantStock component
Shopper: Unauthorized inventory stock manipulation via unlocked variant property in VariantStock component
## Title
Unauthorized inventory stock manipulation via unlocked variant property in VariantStock component
## Description
A lack of authorization control was discovered in the `stockAction()` method in `packages/admin/src/Livewire/Components/Products/VariantStock.php`. The component exposes a `public $variant` property without the `#[Locked]` attribute, so the variant ID is client-mutable via the Livewire wire payload. The `stockAction()` returns an Action with no `->authorize(...)` chain, meaning any authenticated admin-panel session, including browse-only staff who hold zero edit permissions, can call this action to adjust inventory levels for any product variant. The combinatio
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://github.com/shopperlabs/shopper/commit/bf72e2753e21296184596d507336c7d65ecd46ffhttps://github.com/shopperlabs/shopper/pull/570https://github.com/shopperlabs/shopper/releases/tag/v2.9.2https://github.com/shopperlabs/shopper/security/advisories/GHSA-g3f9-g5vj-p62fhttps://github.com/shopperlabs/shopper/security/advisories/GHSA-g3f9-g5vj-p62f
2026-09-15
Published