Junglewise Threat Intelligence

CVE-2026-39250: Innoshop authorization bypass via improper Sanctum token validation

CVE-2026-39250 · Severity: info · CVSS 8.8 · Published 2026-05-19

Executive brief

Innoshop, an e-commerce platform for international retail, contains a security flaw that allows regular customers to access administrative backend interfaces. By simply logging into a standard customer account, an attacker can gain the same privileges as a site administrator. This could lead to the theft of customer data, modification of website templates, or full control over the online store's operations.

Technical details

An authorization vulnerability exists in Innoshop 0.6.0 due to an insecure implementation of Laravel Sanctum authentication. In the 'panel-api.php' routes, administrative interfaces only require the 'auth:sanctum' middleware without specifying a distinct guard or provider for administrators versus customers. Because the Customer model uses the 'HasApiTokens' trait, Sanctum validates a customer's frontend token and identifies them as a valid authenticated user for backend routes. An attacker can register a frontend account, obtain a token, and then use that token to perform administrative actions such as accessing user databases or editing site templates.

Affected products

  • Innoshop Innoshop 0.6.0

Timeline

  • 2026-05-19: disclosed: Vulnerability details and PoC published via GitHub Gist.
  • 2026-05-19: advisory: CVE-2026-39250 published.

References