CVE-2026-108696
CoreShop through 1.5.5 Authorization Bypass via OrderController OrderConfirm and SendReship
CVSS Score
4.3
EPSS Score
0.0%
EPSS Percentile
0th
CoreShop through 1.5.5 contains an authorization bypass vulnerability in the OrderController that allows authenticated customers to act on other customers' orders by supplying user-controlled ids. Attackers can omit the data field in OrderConfirm or supply another reshipId to SendReship to confirm receipt of others' orders and overwrite return tracking details.
| CWE | CWE-639 |
| Vendor | coreunion |
| Product | coreshop |
| Published | Oct 11, 2026 |
Stay Ahead of the Next One
Get instant alerts for coreunion coreshop
Be the first to know when new medium vulnerabilities affecting coreunion coreshop are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
CVSS v3 Breakdown
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N Attack Vector
Network
Attack Complexity
Low
Privileges Required
Low
User Interaction
None
Scope
Unchanged
Confidentiality
None
Integrity
Low
Availability
None
Affected Versions
CoreUnion / CoreShop
0 โค 1.5.5
References
hackmd.io: https://hackmd.io/@1ExmmukzRMWN7B4gQ4W-4Q/SkVjopPsGe github.com: https://github.com/CoreUnion/CoreShop/blob/ca7408b025bc5f3fd5957a79618ffe991c4e91ab/CoreCms.Net.Web.WebApi/Controllers/OrderController.cs#L281-L294 github.com: https://github.com/CoreUnion/CoreShop/blob/ca7408b025bc5f3fd5957a79618ffe991c4e91ab/CoreCms.Net.Web.WebApi/Controllers/OrderController.cs#L422-L458 github.com: https://github.com/CoreUnion/CoreShop/blob/ca7408b025bc5f3fd5957a79618ffe991c4e91ab/CoreCms.Net.Services/Order/CoreCmsOrderServices.cs#L2048-L2060 github.com: https://github.com/CoreUnion/CoreShop vulncheck.com: https://www.vulncheck.com/advisories/coreshop-through-1.5.5-authorization-bypass-via-ordercontroller-orderconfirm-and-sendreship
Credits
hieuPenguinnn