CVE-2026-56831

Shopper is a Headless e-commerce Admin Panel. Prior to 2.9.0, the /cpanel/discounts administrative interface accepts negative fixed_amount discount values, persists them in sh_discounts, and passes them through vendor/shopper/cart/src/Discounts/DiscountCalculator.php and vendor/shopper/cart/src/Pipelines/Calculate.php without enforcing a positive-value invariant. Because the calculation subtracts discountTotal from the subtotal, a negative discount increases the resulting order total instead of reducing it. Malformed discount records can therefore cause incorrect pricing and financial data integrity failures, although the advisory does not establish a customer-facing exploitation path. This issue is fixed in version 2.9.0.
Configurations

No configuration.

History

16 Sep 2026, 15:17

Type Values Removed Values Added
References () https://github.com/shopperlabs/shopper/security/advisories/GHSA-5vf4-452p-jjhf - () https://github.com/shopperlabs/shopper/security/advisories/GHSA-5vf4-452p-jjhf -

Information

Published : 2026-09-15 18:17

Updated : 2026-09-16 15:17


NVD link : CVE-2026-56831

Mitre link : CVE-2026-56831

CVE.ORG link : CVE-2026-56831


JSON object : View

Products Affected

No product.

CWE
CWE-20

Improper Input Validation