{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/cpes/cpe2.3ashopperframework/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:shopper:framework:*:*:*:*:*:*:*:*"],"_cs_cves":[],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["shopper/framework (\u003c 2.9.2)","shopper/framework (\u003e= 2.8.0, \u003c 2.9.2)"],"_cs_severities":["high"],"_cs_tags":["web-application","privilege-escalation","auth-bypass","web-vulnerability","authorization-bypass","shopper","cve-2026-56828","cms"],"_cs_type":"advisory","_cs_vendors":["Shopper"],"content_html":"\u003cp\u003eShopper framework versions prior to 2.9.2 are vulnerable to an authorization bypass in the \u003ccode\u003eCollectionProducts\u003c/code\u003e Livewire component. The vulnerability stems from two primary issues: the \u003ccode\u003ecollection\u003c/code\u003e property is not locked, allowing arbitrary modification of the collection ID by the client, and the delete and bulk-delete actions lack proper authorization checks. An authenticated user possessing only the \u003ccode\u003ebrowse_collections\u003c/code\u003e role can manipulate Livewire network payloads to target and empty any collection within the store's database. This vulnerability effectively escalates a user's privileges, allowing them to perform destructive actions against storefront catalog groupings and promotions without the necessary \u003ccode\u003eedit_collections\u003c/code\u003e permissions. This impacts organizations relying on Shopper for e-commerce catalog management, as an attacker can systematically detach products from collections, disrupting site functionality and promotional campaigns.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eAttacker authenticates to the admin panel using valid, low-privileged credentials (e.g., \u003ccode\u003ebrowse_collections\u003c/code\u003e only).\u003c/li\u003e\n\u003cli\u003eAttacker inspects the \u003ccode\u003eCollectionProducts\u003c/code\u003e Livewire component to identify the target collection ID and the component snapshot structure.\u003c/li\u003e\n\u003cli\u003eAttacker captures the XSRF token and active session cookie to prepare the authenticated network request.\u003c/li\u003e\n\u003cli\u003eAttacker constructs a malicious POST request targeting the \u003ccode\u003e/shopper/livewire/update\u003c/code\u003e endpoint.\u003c/li\u003e\n\u003cli\u003eAttacker replaces the legitimate \u003ccode\u003ecollection\u003c/code\u003e ID within the Livewire component snapshot data with an arbitrary target collection ID.\u003c/li\u003e\n\u003cli\u003eAttacker invokes the \u003ccode\u003ecallBulkAction\u003c/code\u003e method within the payload, specifying the 'delete' action and a list of product IDs to detach.\u003c/li\u003e\n\u003cli\u003eThe server processes the request without verifying the caller's authorization or validating the component state.\u003c/li\u003e\n\u003cli\u003eTargeted products are detached from the specified collection, resulting in a loss of catalog integrity.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eThe successful exploitation of this vulnerability allows unauthorized users to detach products from any collection in the database. This causes immediate disruption to storefront catalog groupings, landing pages, and promotional activities linked to these collections. Because the attacker can target any collection ID, the scope of impact is the entire catalog database rather than just the collections associated with their assigned permissions.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eUpgrade \u003ccode\u003eshopper/framework\u003c/code\u003e to version 2.9.2 or later immediately to patch the missing authorization and property locking.\u003c/li\u003e\n\u003cli\u003eAudit administrative roles to ensure the least-privilege principle is applied and monitor for unauthorized \u003ccode\u003ecallBulkAction\u003c/code\u003e requests in server logs.\u003c/li\u003e\n\u003cli\u003eValidate that all Livewire components sensitive to user input use the \u003ccode\u003e#[Locked]\u003c/code\u003e attribute to prevent client-side property modification.\u003c/li\u003e\n\u003c/ol\u003e\n","date_modified":"2026-09-12T00:57:58Z","date_published":"2026-09-12T00:57:35Z","id":"https://feed.craftedsignal.io/briefs/2026-09-shopper-auth-bypass/","summary":"An authorization bypass vulnerability in the Shopper framework allows authenticated users with limited privileges to perform unauthorized product deletions across any collection in the database.","title":"Authorization Bypass in Shopper Framework CollectionProducts Component","url":"https://feed.craftedsignal.io/briefs/2026-09-shopper-auth-bypass/"}],"language":"en","title":"CraftedSignal Threat Feed - Cpe:2.3:a:shopper:framework:*:*:*:*:*:*:*:*","version":"https://jsonfeed.org/version/1.1"}