Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2026-56829— Shopper: Unauthorized inventory stock manipulation via unlocked variant property in VariantStock component

Quick assessment

Affected
shopperlabs shopper
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

Shopper 是一个无头(Headless)电子商务管理面板。在 2.9.2 版本之前, 中的 方法在缺少 权限授权的情况下被暴露,并且由于缺少 Livewire 的 属性,其公开变量 可被客户端任意修改。因此,任何已认证的管理面板用户(包括仅拥有 权限的普通员工)都可以通过组件状态选择任意的产品变体(variant)和库存位置(inventory location),然后提交正数或负数的数量调整请求。这使得仅具备浏览权限的员工能够针对当前页面之外的任意变体,恶意增加库存、减少库存或强制将其设置为缺货状态。该问题

CVSS 8.1 · High

Affected Version Matrix 1

VendorProduct Version RangeStatus
shopperlabs shopper < 2.9.2 affected
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-56829

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Shopper: Unauthorized inventory stock manipulation via unlocked variant property in VariantStock component
Source: CVE Program / CVE List V5
Vulnerability Description
Shopper is a Headless e-commerce Admin Panel. Prior to 2.9.2, packages/admin/src/Livewire/Components/Products/VariantStock.php exposes stockAction() without edit_product_variants authorization and leaves public $variant client mutable because it lacks the Livewire Locked attribute. Any authenticated admin-panel user, including staff with only browse_products, can select an arbitrary product variant and inventory location through component state, then submit a positive or negative quantity adjustment. This permits browse-only staff to inflate stock, reduce stock, or force out-of-stock states for variants outside the current page. This issue is fixed in version 2.9.2.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H
Source: CVE Program / CVE List V5
Vulnerability Type
授权机制缺失
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
shopperlabs shopper < 2.9.2 -

II. Public POCs for CVE-2026-56829

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-56829

登录查看更多情报信息。

Patches & Fixes for CVE-2026-56829 (2)

Vendor Pages for CVE-2026-56829 (1)

Same Patch Batch · shopperlabs · 2026-09-15 · 5 CVEs total

CVE-2026-56827 8.1 HIGH Shopper: Authorization bypass in Filament bulk actions allows browse-only staff to mass-de
CVE-2026-56825 8.1 HIGH Shopper: Missing authorization on product removal actions in CollectionProducts component
CVE-2026-56830 6.5 MEDIUM Shopper: Incomplete fix for GHSA-h4mp-g9c6-xwph: Media sub-form store() still lacks author
CVE-2026-56831 6.5 MEDIUM Shopper: Negative discount values accepted and propagated through order calculation pipeli

IV. Related Vulnerabilities

V. Comments for CVE-2026-56829

No comments yet


Leave a comment