CVE-2026-21447

HIGH

Webkul Bagisto < 2.3.10 - Improper Access Control

Title source: rule
STIX 2.1

Description

Bagisto is an open source laravel eCommerce platform. Prior to version 2.3.10, an Insecure Direct Object Reference vulnerability in the customer order reorder function allows any authenticated customer to add items from another customer's order to their own shopping cart by manipulating the order ID parameter. This exposes sensitive purchase information and enables potential fraud. Version 2.3.10 patches the issue.

Scores

CVSS v3 7.1
EPSS 0.0002
EPSS Percentile 3.8%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N

CISA SSVC

Vulnrichment
Exploitation poc
Automatable yes
Technical Impact partial

Details

CWE
CWE-639 CWE-284
Status published
Products (2)
bagisto/bagisto 0 - 2.3.10Packagist
webkul/bagisto < 2.3.10
Published Jan 02, 2026
Tracked Since Feb 18, 2026