{"id":"CVE-2026-47740","aliases":["GHSA-f946-9qp6-vgch"],"url":"https://o3.security/vulnerability/CVE-2026-47740","summary":"Shopper: Authorization bypass in multiple Livewire admin components","details":"## Impact\n\nMultiple Livewire components in the admin panel allowed an authenticated low-privilege user to mutate data without the required permission:\n\n- Order detail Filament actions (cancel, mark paid, mark complete, capture payment, archive, start processing) were callable with `read_orders` only and did not require `edit_orders`. `capturePayment` could trigger an actual PSP capture.\n- Order shipments table actions (mark delivered, edit tracking) were callable with `browse_orders` only.\n- Sub-form Livewire components for products (Edit, Inventory, Seo, Shipping, Files) had no authorization on `store()`, so any authenticated panel user could mutate product data without `edit_products`.\n- `Settings/Team/Index` had no `mount()` authorization at all — any authenticated user could create roles and delete other users.\n- `Settings/Team/RolePermission` gated its write actions on the read-only `view_users` permission, allowing privilege escalation via the RBAC system itself.\n- `PaymentMethods`, `Currencies`, `Carriers` table toggles and per-record actions had no per-action permission check.\n- `Customers/Create::store()` re-passed a Hidden `_password` form field into the create payload.\n\nSeveral public Eloquent model properties on Livewire components were not `#[Locked]`, allowing client-side ID tampering.\n\nA stored XSS surface existed on the product barcode field, which is rendered through `DNS1DFacade::getBarcodeHTML()` with `{!! !!}`.\n\n## Patches\n\nFixed in `v2.8.0`. Upgrade via:\n\n```bash\ncomposer require shopper/admin:^2.8 shopper/cart:^2.8 shopper/core:^2.8\n```\n\n```shell\nphp artisan migrate\n```\n\n## Workarounds\n\nNone. Upgrade to `v2.8.0`.\n\n## Resources\n\n- Pull request: https://github.com/shopperlabs/shopper/pull/511\n- CWE-862 Missing Authorization\n- CWE-285 Improper Authorization","published":"2026-05-29T18:03:54.473Z","modified":"2026-08-12T03:51:26.189619683Z","cvss":{"score":8.1,"severity":"HIGH","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N"},"epss":{"score":0.00258,"percentile":0.17052,"asOf":"2026-08-24"},"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"Packagist","name":"shopper/framework","fixedVersion":"2.8.0"}],"fix":{"url":"https://github.com/shopperlabs/shopper/pull/511","label":"shopperlabs/shopper#511"},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/47xxx/CVE-2026-47740.json"},{"type":"ADVISORY","url":"https://github.com/shopperlabs/shopper/security/advisories/GHSA-f946-9qp6-vgch"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-47740"},{"type":"FIX","url":"https://github.com/shopperlabs/shopper/pull/511"},{"type":"WEB","url":"https://github.com/shopperlabs/shopper/issues/510"},{"type":"WEB","url":"https://github.com/shopperlabs/shopper/commit/fcd0c5920588702df5b874f432b1042abd77a50b"},{"type":"PACKAGE","url":"https://github.com/shopperlabs/shopper"},{"type":"WEB","url":"https://github.com/shopperlabs/shopper/releases/tag/v2.8.0"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-12T03:51:26.189619683Z"}}