Stats Digest Feeds
โ† Back to all CVEs

CVE-2026-101139

LOW NVD
CVSS Score 2.7
Severity LOW
Published Sep 28, 2026
Vendor unknown

Description

A vulnerability was detected in Webkul Bagisto up to 2.4.6. This impacts an unknown function of the file /admin/sales/invoices/mass-update/state of the component Invoice Mass Status Update. Performing a manipulation results in missing authorization. The attack can be initiated remotely. The exploit is now public and may be used. The vendor was contacted early about this disclosure.

References