Junglewise Threat Intelligence

CVE-2026-47740: Shopper Missing Authorization in Order and Shipment Actions

CVE-2026-47740 · Severity: high · CVSS 8.1 · Published 2026-05-29

Technologies: shopper/framework (Packagist). Vendors: Packagist, Shopper Labs.

Executive brief

Shopper is a headless e-commerce administration panel used to manage online stores. A security flaw allowed staff members with limited 'read-only' access to perform restricted actions, such as canceling orders, marking them as complete, or even triggering actual payment captures from customers. This could lead to unauthorized financial transactions and disruption of business operations by low-privileged internal users.

Technical details

An authorization bypass vulnerability exists in Shopper's admin panel due to missing permission checks on several Filament actions. Specifically, actions such as 'cancel', 'mark paid', 'mark complete', 'capture payment', 'archive', and 'start processing' were incorrectly accessible to users with only 'read_orders' permissions instead of requiring 'edit_orders'. Additionally, shipment-related actions like 'mark delivered' and 'edit tracking' only required 'browse_orders' access. An authenticated attacker with low-level read access can exploit this to manipulate the order lifecycle and trigger real-world payment captures via Payment Service Providers (PSPs). The issue is resolved in version 2.8.0 by implementing proper authorization gates on these actions.

Affected products

  • Shopper Labs shopper/framework < 2.8.0

Timeline

  • 2026-05-11: patched: Fix merged in pull request #511
  • 2026-05-11: advisory: GitHub Security Advisory published
  • 2026-05-29: disclosed: CVE-2026-47740 published to NVD

References

Related threats