CVE-2026-47741: CWE-362: Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition') in shopperlabs shopper
CVE-2026-47741 is a race condition vulnerability in shopperlabs' shopper product prior to version 2.8.0. The issue occurs because the system creates an order before properly checking and incrementing the discount usage counter, allowing the discount's usage limit to be exceeded silently under concurrent checkout conditions. This results in orders being processed with discounts applied beyond their intended usage limits without alerting the merchant. The vulnerability has a medium severity with a CVSS score of 5.9 and is fixed in version 2.8.0.
AI Analysis
Technical Summary
Shopperlabs' shopper product versions before 2.8.0 suffer from a race condition (CWE-362) in the CreateOrderFromCartAction::execute function. The order creation process does not synchronize the increment of the discount's total_use counter with the order creation, allowing concurrent checkouts to exceed the discount's global usage_limit. This leads to orders being committed with discounts applied beyond their allowed usage, without merchant notification. The vulnerability is addressed in version 2.8.0.
Potential Impact
The vulnerability allows the discount usage limit to be silently exceeded during high concurrency events such as flash sales or viral coupon campaigns. This can result in financial loss for merchants due to over-redemption of discounts. There is no impact on confidentiality or availability reported. No known exploits are currently in the wild.
Mitigation Recommendations
Upgrade to shopper version 2.8.0 or later, where this race condition vulnerability is fixed. Patch status is not explicitly stated but the vendor has released version 2.8.0 to address the issue. Until upgrading, merchants should be aware that discount usage limits may be exceeded under high concurrency.
CVE-2026-47741: CWE-362: Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition') in shopperlabs shopper
Description
CVE-2026-47741 is a race condition vulnerability in shopperlabs' shopper product prior to version 2.8.0. The issue occurs because the system creates an order before properly checking and incrementing the discount usage counter, allowing the discount's usage limit to be exceeded silently under concurrent checkout conditions. This results in orders being processed with discounts applied beyond their intended usage limits without alerting the merchant. The vulnerability has a medium severity with a CVSS score of 5.9 and is fixed in version 2.8.0.
CVSS v3.1
Score 5.9medium
Affected software
pkg:github/shopperlabs/shopperRun on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
Shopperlabs' shopper product versions before 2.8.0 suffer from a race condition (CWE-362) in the CreateOrderFromCartAction::execute function. The order creation process does not synchronize the increment of the discount's total_use counter with the order creation, allowing concurrent checkouts to exceed the discount's global usage_limit. This leads to orders being committed with discounts applied beyond their allowed usage, without merchant notification. The vulnerability is addressed in version 2.8.0.
Potential Impact
The vulnerability allows the discount usage limit to be silently exceeded during high concurrency events such as flash sales or viral coupon campaigns. This can result in financial loss for merchants due to over-redemption of discounts. There is no impact on confidentiality or availability reported. No known exploits are currently in the wild.
Mitigation Recommendations
Upgrade to shopper version 2.8.0 or later, where this race condition vulnerability is fixed. Patch status is not explicitly stated but the vendor has released version 2.8.0 to address the issue. Until upgrading, merchants should be aware that discount usage limits may be exceeded under high concurrency.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- GitHub_M
- Date Reserved
- 2026-05-19T22:16:39.504Z
- Cvss Version
- 3.1
- State
- PUBLISHED
- Remediation Level
- null
Threat ID: 6a19dc07e29bf47b50ff85db
Added to database: 05/29/2026, 18:33:43 UTC
Last enriched: 06/05/2026, 21:20:58 UTC
Last updated: 07/31/2026, 19:22:59 UTC
Views: 48
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.