Executive brief
A security flaw has been identified in the FTC E-Commerce Management Panel, a tool used by businesses to manage online stores and sales operations. This vulnerability allows unauthorized individuals to bypass security checks and access sensitive administrative functions without a password. An attacker could exploit this to view private customer data or modify store settings, potentially leading to data theft or operational disruption.
Technical details
A Missing Authentication for Critical Function vulnerability (CWE-306) exists in the FTC E-Commerce Management Panel. The flaw is located within the management interface and allows a remote, unauthenticated attacker to bypass authentication mechanisms by directly accessing sensitive functional endpoints. With a CVSS score of 8.2, the impact includes high confidentiality loss and low integrity impact, as attackers can potentially extract sensitive data or perform unauthorized administrative actions. The issue is resolved in version 1.0.2.
Affected products
- FTC Software IT Services FTC E-Commerce Management Panel before 1.0.2
Timeline
- 2026-07-30: disclosed
- 2026-07-30: advisory