CVE-2026-79411
Deferred Deferred - Pending Action

Privilege Escalation in Webkul Bagisto Admin Panel

Vulnerability report for CVE-2026-79411, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-15

Last updated on: 2026-09-22

Assigner: MITRE

Description

Incorrect privilege assignment in the admin user-management component of Webkul Bagisto 2.4.9 allows an authenticated backend user holding only the settings.users.edit permission to escalate to full administrator. The user-update endpoint (route admin.settings.users.update, UserController::update()) does not verify that the actor is permitted to grant the requested role, does not prevent a user from changing their own role, and does not restrict assignment to roles whose permission set is a subset of the actor's own. By submitting a request that sets role_id to the Administrator role for their own account, a low-privileged administrator gains every admin-panel capability, including store configuration, payment gateway credentials, and customer PII.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-15
Last Modified
2026-09-22
Generated
2026-10-06
AI Q&A
2026-09-16
EPSS Evaluated
2026-10-04
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
webkul bagisto 2.4.9

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This is a privilege escalation vulnerability in Webkul Bagisto 2.4.9 where an authenticated backend user with only settings.users.edit permission can assign themselves the Administrator role. The flaw exists because the user-update endpoint does not verify if the user is allowed to grant the requested role, allows self-assignment, and does not restrict role promotion to more privileged roles.

Detection Guidance

Check for unauthorized role assignments in the admin panel. Look for users with the Administrator role who should not have it. Review logs for POST requests to the /admin/settings/users/update endpoint with role_id set to 1 (Administrator).

Commands: 1) Check database for users with role_id=1: SELECT * FROM users WHERE role_id = 1; 2) Audit logs for suspicious user updates: grep 'settings.users.edit' /path/to/logs/*.log

Impact Analysis

An attacker with limited admin privileges could escalate to full administrator access, gaining control over store configuration, payment gateways, customer PII, and order data. This could lead to complete store takeover without leaving traces in the database.

Compliance Impact

This vulnerability could lead to unauthorized access to sensitive customer data, violating GDPR and HIPAA compliance requirements for data protection and access controls. Full administrative access could result in data breaches and non-compliance penalties.

Mitigation Strategies

Remove the settings.users.edit permission from all non-administrator accounts immediately. Restrict role_id parameter input to only allow roles the user is authorized to assign. Disable self-role modification for non-administrators.

Monitor all admin panel access and user role changes. Consider temporarily disabling the user management interface until a patch is available.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-79411. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart