Junglewise Threat Intelligence

CVE-2026-50986: 202-ecommerce PrestaShop Administrative Mandate CSRF in payment validation

CVE-2026-50986 · Severity: info · CVSS 5.3 · Published 2026-07-31

Executive brief

A security vulnerability exists in the Administrative Mandate payment module for PrestaShop, which allows public sector or corporate entities to pay via administrative orders. An attacker can trick the system into confirming or creating orders in an 'awaiting' status without proper authorization. This could lead to fraudulent order placement or the use of this payment method in regions where it is not officially supported.

Technical details

The totadministrativemandate module (Administrative Mandate) for PrestaShop fails to implement CSRF tokens within its payment validation controller. This CWE-352 vulnerability allows a remote attacker to bypass intended payment restrictions by hijacking or forging a link to confirm an order that is currently in an 'awaiting' status. According to the researcher, this can also be used to create orders using the Administrative Mandate method in countries where the method is not explicitly enabled. The issue is resolved in version 1.8.2.

Affected products

  • 202-ecommerce totadministrativemandate (Administrative Mandate) < 1.8.2

Timeline

  • 2026-04-09: disclosed: Discovered during internal audit by 202-ecommerce
  • 2026-05-15: patched: Version 1.8.2 released on PrestaShop Marketplace
  • 2026-07-31: advisory: CVE published by NVD

References