Threats Tagged 'cve-2026-56826'
View all threats tagged with 'cve-2026-56826'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'cve-2026-56826'
Click on any threat for detailed analysis and mitigation recommendations
0 A privilege escalation vulnerability exists in the Shopper Framework's Settings area where four Livewire components allow authenticated users with only the coarse 'access_setting' permission to perform destructive delete actions without proper server-side authorization. This flaw enables deletion of tax zones, tax rates, shipping zones, and carrier options, which are critical for checkout processes. The affected components lack per-resource permission checks, allowing low-privileged users to delete these records directly via Livewire endpoints. This breaks shipping-rate calculations, removes region-scoped payment methods, and corrupts tax resolution at checkout. The issue affects versions >=2.0.0 and <2.9.2 and has a CVSS score of 5.4 (medium severity). A patch is available. Join the discussion | GCVE Database | 09/11/2026, 21:28:20 UTC Added: 09/12/2026, 00:43:39 UTC |
Showing 1 to 1 of 1 result