Junglewise Threat Intelligence

CVE-2026-2347: Akilli Commerce E-Commerce Website authorization bypass in session management

CVE-2026-2347 · Severity: critical · CVSS 9.8 · Published 2026-05-14

Technologies: Akilli Commerce Software Technologies Ltd. Co. E-Commerce Website. Vendors: Akilli Commerce Software Technologies Ltd. Co..

Executive brief

Akilli Commerce E-Commerce Website software is vulnerable to an authorization bypass that allows attackers to hijack user sessions. This software is used to power online retail storefronts and manage customer transactions. An exploit could allow an unauthorized individual to take over customer accounts, potentially accessing sensitive personal information or performing fraudulent purchases, which poses a significant risk to customer data privacy and business reputation.

Technical details

An Insecure Direct Object Reference (IDOR) vulnerability, specifically an authorization bypass through a user-controlled key (CWE-639), exists in the Akilli Commerce E-Commerce Website software prior to version 4.5.001. The flaw allows a remote, unauthenticated attacker to manipulate session-related keys or identifiers to hijack active user sessions. By exploiting this, an attacker can gain full access to other users' accounts without requiring valid credentials. The vulnerability is reachable over the network with low attack complexity and no user interaction required. Users are advised to upgrade to version 4.5.001 or later to remediate the issue.

Affected products

  • Akilli Commerce Software Technologies Ltd. Co. E-Commerce Website before 4.5.001

Timeline

  • 2026-05-14: disclosed
  • 2026-05-14: advisory

References

Related threats