Junglewise Threat Intelligence

CVE-2026-84186: PrestaShop IP address spoofing in getRemoteAddr()

CVE-2026-84186 · Severity: info · CVSS 6.9 · Published 2026-09-07

Technologies: PrestaShop. Vendors: PrestaShop.

Executive brief

PrestaShop is a popular open-source e-commerce platform used to build online stores. This vulnerability allows attackers to forge their source IP address via the X-Forwarded-For header, bypassing IP-based security controls like maintenance mode allowlists and enabling tampering with security logs and evasion of fraud detection systems.

Technical details

This vulnerability is an access control issue (CWE-290) in the Tools::getRemoteAddr() function where PrestaShop incorrectly trusts and processes the X-Forwarded-For header when running behind a reverse proxy, load balancer, or CDN. An unauthenticated remote attacker can supply an arbitrary IP address via this header, and the application will use it instead of the real client IP from trusted infrastructure. This allows bypassing IP-based allowlists, forging audit and security logs, and evading geolocation checks, fraud detection, and request rate limiting. The vulnerability has been patched in PrestaShop versions 9.1.5 and 8.2.8.

Affected products

  • PrestaShop PrestaShop before 8.2.8 and 9.1.5

Timeline

  • 2026-09-07: disclosed
  • 2026-09-07: patched: Fixed in versions 9.1.5 and 8.2.8

References

Related threats