CVE-2026-101139
Webkul Bagisto Invoice Mass Status Update state authorization
CVSS Score
2.7
EPSS Score
0.0%
EPSS Percentile
0th
A vulnerability was detected in Webkul Bagisto up to 2.4.6. This impacts an unknown function of the file /admin/sales/invoices/mass-update/state of the component Invoice Mass Status Update. Performing a manipulation results in missing authorization. The attack can be initiated remotely. The exploit is now public and may be used. The vendor was contacted early about this disclosure.
| CWE | CWE-862 CWE-863 |
| Vendor | webkul |
| Product | bagisto |
| Published | Sep 28, 2026 |
| Last Updated | Sep 28, 2026 |
Stay Ahead of the Next One
Get instant alerts for webkul bagisto
Be the first to know when new low vulnerabilities affecting webkul bagisto are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
CVSS v3 Breakdown
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:N/E:P/RL:X/RC:R Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability
Affected Versions
Webkul / Bagisto
2.4.0 2.4.1 2.4.2 2.4.3 2.4.4 2.4.5 2.4.6
References
Credits
๐ ciphersecuritylabs (VulDB User) VulDB CNA Team