CVE-2026-47742: CWE-862: Missing Authorization in shopperlabs shopper
Shopper is a Headless e-commerce Admin Panel. Prior to 2.8.0, Sub-form Livewire components used in the product editor (Edit, Inventory, Seo, Shipping, Files) had no authorization on their store() method. Any authenticated panel user, regardless of role, could mutate any product's pricing, stock, SEO metadata, shipping dimensions, and attached media without holding edit_products. The affected components accepted the product ID as a public Livewire property without #[Locked], so an attacker could also target an arbitrary product by tampering with the wire payload from the client. This vulnerability is fixed in 2.8.0.
AI Analysis
Technical Summary
Shopper versions before 2.8.0 have a missing authorization vulnerability (CWE-862) in the Livewire sub-form components of the product editor. The store() methods in these components do not enforce authorization, allowing any authenticated panel user, regardless of role, to mutate product data such as pricing, inventory, SEO metadata, shipping details, and media attachments. The product ID is exposed as a public Livewire property without the #[Locked] attribute, enabling attackers to manipulate the wire payload to affect arbitrary products. This vulnerability is resolved in shopper version 2.8.0.
Potential Impact
An authenticated user without the edit_products permission can modify critical product information including pricing, stock levels, SEO metadata, shipping dimensions, and attached media. This could lead to unauthorized changes in product data, potentially impacting business operations and data integrity. There is no indication of confidentiality or availability impact. No known exploits are reported in the wild.
Mitigation Recommendations
This vulnerability is fixed in shopper version 2.8.0. Users should upgrade to version 2.8.0 or later to remediate this issue. No official patch or temporary fix is documented beyond upgrading. Since this is not a cloud service, remediation depends on applying the vendor's fixed version.
CVE-2026-47742: CWE-862: Missing Authorization in shopperlabs shopper
Description
Shopper is a Headless e-commerce Admin Panel. Prior to 2.8.0, Sub-form Livewire components used in the product editor (Edit, Inventory, Seo, Shipping, Files) had no authorization on their store() method. Any authenticated panel user, regardless of role, could mutate any product's pricing, stock, SEO metadata, shipping dimensions, and attached media without holding edit_products. The affected components accepted the product ID as a public Livewire property without #[Locked], so an attacker could also target an arbitrary product by tampering with the wire payload from the client. This vulnerability is fixed in 2.8.0.
CVSS v3.1
Score 6.5medium
Affected software
pkg:github/shopperlabs/shopperRun on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
Shopper versions before 2.8.0 have a missing authorization vulnerability (CWE-862) in the Livewire sub-form components of the product editor. The store() methods in these components do not enforce authorization, allowing any authenticated panel user, regardless of role, to mutate product data such as pricing, inventory, SEO metadata, shipping details, and media attachments. The product ID is exposed as a public Livewire property without the #[Locked] attribute, enabling attackers to manipulate the wire payload to affect arbitrary products. This vulnerability is resolved in shopper version 2.8.0.
Potential Impact
An authenticated user without the edit_products permission can modify critical product information including pricing, stock levels, SEO metadata, shipping dimensions, and attached media. This could lead to unauthorized changes in product data, potentially impacting business operations and data integrity. There is no indication of confidentiality or availability impact. No known exploits are reported in the wild.
Mitigation Recommendations
This vulnerability is fixed in shopper version 2.8.0. Users should upgrade to version 2.8.0 or later to remediate this issue. No official patch or temporary fix is documented beyond upgrading. Since this is not a cloud service, remediation depends on applying the vendor's fixed version.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- GitHub_M
- Date Reserved
- 2026-05-19T22:16:39.504Z
- Cvss Version
- 3.1
- State
- PUBLISHED
- Remediation Level
- null
Threat ID: 6a19dc07e29bf47b50ff85e0
Added to database: 05/29/2026, 18:33:43 UTC
Last enriched: 06/05/2026, 21:03:12 UTC
Last updated: 07/31/2026, 19:22:59 UTC
Views: 51
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.