CVE-2026-79410: n/a
Improper validation of the quantity parameter in the add-to-cart path of Webkul Bagisto v2.4.9 allows authenticated attackers to reduce their order total below the legitimate price of shippable goods.
AI Analysis
Technical Summary
CVE-2026-79410 describes an improper validation vulnerability in the quantity parameter of the add-to-cart functionality in Webkul Bagisto version 2.4.9. Authenticated attackers can exploit this flaw to alter the quantity value, resulting in a reduced order total that is less than the actual price of the goods being purchased.
Potential Impact
Exploitation of this vulnerability allows authenticated users to pay less than the legitimate price for shippable goods, potentially causing financial loss to merchants using the affected software.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until an official fix is available, restrict access to trusted users and monitor for suspicious order manipulations related to quantity parameters.
CVE-2026-79410: n/a
Description
Improper validation of the quantity parameter in the add-to-cart path of Webkul Bagisto v2.4.9 allows authenticated attackers to reduce their order total below the legitimate price of shippable goods.
CVSS v3.1
Score 8.1high
Affected software
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
CVE-2026-79410 describes an improper validation vulnerability in the quantity parameter of the add-to-cart functionality in Webkul Bagisto version 2.4.9. Authenticated attackers can exploit this flaw to alter the quantity value, resulting in a reduced order total that is less than the actual price of the goods being purchased.
Potential Impact
Exploitation of this vulnerability allows authenticated users to pay less than the legitimate price for shippable goods, potentially causing financial loss to merchants using the affected software.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until an official fix is available, restrict access to trusted users and monitor for suspicious order manipulations related to quantity parameters.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- mitre
- Date Reserved
- 2026-08-25T00:00:00.000Z
- State
- PUBLISHED
Threat ID: 6aa9963d55bf5e2cf53fe83c
Added to database: 09/15/2026, 19:02:21 UTC
Last enriched: 09/15/2026, 19:17:02 UTC
Last updated: 09/16/2026, 02:21:22 UTC
Views: 8
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.