Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Tue, 29 Sep 2026 16:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A vulnerability was detected in Webkul Bagisto up to 2.4.6. This impacts an unknown function of the file /admin/sales/invoices/mass-update/state of the component Invoice Mass Status Update. Performing a manipulation results in missing authorization. The attack can be initiated remotely. The exploit is now public and may be used. The vendor was contacted early about this disclosure. | A vulnerability was detected in Webkul Bagisto up to 2.4.6/2.5.0-beta4. This impacts an unknown function of the file /admin/sales/invoices/mass-update/state of the component Invoice Mass Status Update. Performing a manipulation results in missing authorization. The attack can be initiated remotely. The exploit is now public and may be used. Upgrading to version 2.5.0-beta5 will fix this issue. The patch is named 2c34b94d0313824ce98efee8aef8ee141d9b89d0. It is recommended to apply a patch to fix this issue. The vendor confirms: "[W]e run continuous automated AI-assisted security scanning across the Bagisto codebase. The behaviour you describe has already been identified and reproduced internally, and it is actively being fixed rather than triaged from scratch." |
| References |
| |
| Metrics |
cvssV2_0
|
cvssV2_0
|
Mon, 28 Sep 2026 20:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 28 Sep 2026 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A vulnerability was detected in Webkul Bagisto up to 2.4.6. This impacts an unknown function of the file /admin/sales/invoices/mass-update/state of the component Invoice Mass Status Update. Performing a manipulation results in missing authorization. The attack can be initiated remotely. The exploit is now public and may be used. The vendor was contacted early about this disclosure. | |
| Title | Webkul Bagisto Invoice Mass Status Update state authorization | |
| First Time appeared |
Webkul
Webkul bagisto |
|
| Weaknesses | CWE-862 CWE-863 |
|
| CPEs | cpe:2.3:a:webkul:bagisto:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Webkul
Webkul bagisto |
|
| References |
| |
| Metrics |
cvssV2_0
|
Status: PUBLISHED
Assigner: VulDB
Published:
Updated: 2026-09-29T16:30:39.149Z
Reserved: 2026-09-28T07:42:38.014Z
Link: CVE-2026-101139
Updated: 2026-09-28T19:26:14.861Z
Status : Deferred
Published: 2026-09-28T19:16:47.940
Modified: 2026-09-29T17:17:05.317
Link: CVE-2026-101139
No data.
OpenCVE Enrichment
Updated: 2026-09-28T20:30:06Z