CVE-2026-79410
Deferred Deferred - Pending Action

Improper Quantity Validation in Webkul Bagisto

Vulnerability report for CVE-2026-79410, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-15

Last updated on: 2026-09-22

Assigner: MITRE

Description

Improper validation of the quantity parameter in the add-to-cart path of Webkul Bagisto v2.4.9 allows authenticated attackers to reduce their order total below the legitimate price of shippable goods.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-15
Last Modified
2026-09-22
Generated
2026-10-06
AI Q&A
2026-09-16
EPSS Evaluated
2026-10-04
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
webkul bagisto 2.4.9

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-20 The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability in Bagisto v2.4.9 allows authenticated users to manipulate the cart total by submitting negative quantities during the add-to-cart process. The system fails to validate the quantity parameter for positivity, enabling attackers to reduce their order total below the legitimate price of goods. The issue stems from improper handling in methods like handleQuantity() and lack of validation in endpoints such as wishlist move-to-cart and bundle option quantity paths.

Detection Guidance

To detect this vulnerability, monitor API requests to the Bagisto endpoints for negative quantity parameters. Check logs for POST requests to /api/customer/wishlist/{id}/move-to-cart or /api/checkout/cart with negative values in quantity or bundle_option_qty fields. Review cart totals for negative values before checkout.

  • Inspect database records for non-positive quantities or negative order totals, especially in bundle orders.
Impact Analysis

An attacker can exploit this to drastically reduce their cart total before checkout. For example, adding a high-value item and then using negative quantities on another item to lower the overall payment amount. The merchant may ship real goods while receiving a manipulated, lower payment, resulting in financial loss. The database clamps negative quantities to zero but the negative total persists.

Compliance Impact

This vulnerability could lead to financial loss for merchants by allowing attackers to manipulate order totals, potentially violating financial transaction integrity requirements under regulations like GDPR (data protection) and HIPAA (if payment data is involved).

Mitigation Strategies

Implement input validation to enforce positive quantities in the handleQuantity() method and endpoints. Add server-side checks for quantity parameters in wishlist and bundle option paths. Ensure database constraints prevent negative values from affecting totals.

  • Audit existing cart and order data for negative quantities or totals and correct them immediately.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-79410. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart