Shopper is a Headless e-commerce Admin Panel. Prior to 2.9.2, an earlier product sub-form hardening change left store() in packages/admin/src/Livewire/Components/Products/Form/Media.php without the edit_products authorization check used by sibling sub-forms. An authenticated staff user with browse_products can invoke the Livewire store action and replace the thumbnail and gallery images for a product whose Media component was initialized, even without product-edit permission. The product binding is locked, so the attacker cannot redirect the update to an arbitrary product through client-side ID substitution, and the impact is limited to products whose edit pages were loaded. This issue is fixed in version 2.9.2.
References
Configurations
No configuration.
History
No history.
Information
Published : 2026-09-15 18:17
Updated : 2026-09-15 20:17
NVD link : CVE-2026-56830
Mitre link : CVE-2026-56830
CVE.ORG link : CVE-2026-56830
JSON object : View
Products Affected
No product.
CWE
CWE-862
Missing Authorization
