CVE-2026-56830
published 2026-09-15CVE-2026-56830: Shopper is a Headless e-commerce Admin Panel. Prior to 2.9.2, an earlier product sub-form hardening change left store() in…
PriorityP340medium6.5CVSS 3.1
AVNACLPRLUINSUCNIHAN
EPSS
0.36%
30.1th percentile
Shopper is a Headless e-commerce Admin Panel. Prior to 2.9.2, an earlier product sub-form hardening change left store() in packages/admin/src/Livewire/Components/Products/Form/Media.php without the edit_products authorization check used by sibling sub-forms. An authenticated staff user with browse_products can invoke the Livewire store action and replace the thumbnail and gallery images for a product whose Media component was initialized, even without product-edit permission. The product binding is locked, so the attacker cannot redirect the update to an arbitrary product through client-side ID substitution, and the impact is limited to products whose edit pages were loaded. This issue is fixed in version 2.9.2.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| shopper | framework | >= 0 < 2.9.2 | 2.9.2 |
| shopperlabs | shopper | < 2.9.2 | 2.9.2 |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
Shopper Media Media.php store improper authorization
vuldb·2026-09-12
CVE-2026-56830 [LOW] Shopper Media Media.php store improper authorization
A vulnerability described as problematic has been identified in Shopper. This impacts the function store of the file packages/admin/src/Livewire/Components/Products/Form/Media.php of the component Media. Such manipulation leads to improper authorization.
This vulnerability is documented as CVE-2026-56830. The attack can be executed remotely. There is not any exploit available.
GHSA
Shopper: Media sub-form store() still lacks authorization (Incomplete fix for GHSA-h4mp-g9c6-xwph)
ghsa·2026-09-11
CVE-2026-56830 [MEDIUM] CWE-862 Shopper: Media sub-form store() still lacks authorization (Incomplete fix for GHSA-h4mp-g9c6-xwph)
Shopper: Media sub-form store() still lacks authorization (Incomplete fix for GHSA-h4mp-g9c6-xwph)
## Title
Missing authorization on Media sub-form store action allows unpermissioned product media update
## Description
A lack of authorization control on the `store()` method was found in `packages/admin/src/Livewire/Components/Products/Form/Media.php`. The security fix released for GHSA-h4mp-g9c6-xwph added `#[Locked]` to the `$product` property in this file but did not add an `authorize()` call to `store()`. The commit message for that fix (fcd0c59) explicitly names the five repaired sub-form components: Edit, Inventory, Seo, Shipping, Files. Media is absent from that list and absent from the published advisory. As a result, any authenticated admin-panel session, including a staff user
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2026-09-15
Published