Junglewise Threat Intelligence

CVE-2026-79410: Webkul Bagisto improper quantity validation in add-to-cart

CVE-2026-79410 · Severity: high · CVSS 8.1 · Published 2026-09-15

Executive brief

Webkul Bagisto is an e-commerce platform that powers online storefronts. A flaw in how the shopping cart validates product quantities allows authenticated buyers to manipulate their orders and artificially reduce the final price below the legitimate cost of goods, potentially enabling fraud and revenue loss for merchants.

Technical details

The vulnerability is an improper validation flaw in the add-to-cart functionality of Bagisto v2.4.9. The quantity parameter is not sufficiently validated when items are added to the cart, allowing authenticated attackers to bypass business logic controls and reduce their order total below the legitimate price of shippable goods. The attack requires prior authentication and manipulation of cart quantity values. An attacker can achieve unauthorized price reduction and checkout at artificially low amounts, directly impacting merchant revenue.

Affected products

  • Webkul Bagisto v2.4.9

Timeline

  • 2026-09-15: disclosed

References

Related threats