Shopper: Unauthorized inventory stock manipulation

Published September 11, 2026 CVE-2026-56829

Shopper: Unauthorized inventory stock manipulation via unlocked variant property in VariantStock component. Title Unauthorized inventory stock manipulation via unlocked variant property in VariantStock component Description A lack of authorization control was discovered in the stockAction() method in packages/admin/src/Livewire/Components/Products/VariantStock.php.

Severity
HighCVSS 3.1 · 8.1 · github.com
Fix
Fixed in 2.9.2Fix recorded today
Affected versions
before 2.9.2
Weakness
CWE-862Missing Authorization
Affects
shopper/framework

What to do

Update to 2.9.2 or later.

Technical details

Affected software: shopper/framework

Severity breakdown

  • Attack vector Network Requires network access to the vulnerable service
  • Attack complexity Low Low complexity under the assessed conditions
  • Privileges required Low Attacker needs a basic user account
  • User interaction None No victim action needed
  • Scope Unchanged Impact stays within the same security authority
  • Confidentiality impact None No data disclosure
  • Integrity impact High Protected data can be changed with serious impact
  • Availability impact High The service can stop or suffer serious disruption
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H Open in FIRST.org calculator

References