CVE-2026-108696
Received Received - Intake

Authorization Bypass in CoreShop Allows Order Manipulation

Vulnerability report for CVE-2026-108696, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-11

Last updated on: 2026-10-11

Assigner: VulnCheck

Description

CoreShop through 1.5.5 contains an authorization bypass vulnerability in the OrderController that allows authenticated customers to act on other customers' orders by supplying user-controlled ids. Attackers can omit the data field in OrderConfirm or supply another reshipId to SendReship to confirm receipt of others' orders and overwrite return tracking details.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-11
Last Modified
2026-10-11
Generated
2026-10-11
AI Q&A
2026-10-11
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
CoreUnion CoreShop 0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-639 The system's authorization functionality does not prevent one user from gaining access to another user's data or record by modifying the key value identifying the data.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

CoreShop through version 1.5.5 has an authorization bypass flaw in the OrderController. Authenticated customers can manipulate other users' orders by supplying user-controlled IDs. Attackers can omit the data field in OrderConfirm or provide a different reshipId in SendReship to confirm receipt of others' orders and overwrite return tracking details.

Detection Guidance

To detect this vulnerability, monitor API logs for suspicious OrderConfirm or SendReship requests where the data field is omitted or reshipId is manipulated. Check for requests with mismatched user IDs and order IDs. Use tools like Burp Suite or Postman to send test requests to /api/Order/OrderConfirm and /api/Order/SendReship with varying parameters to observe unauthorized access attempts.

Impact Analysis

An attacker could confirm receipt of your orders without payment, disrupting fulfillment. They could also alter return shipment tracking details, potentially causing refund issues or logistical confusion. This requires only a valid authenticated session and knowledge of your order IDs.

Compliance Impact

This vulnerability could lead to unauthorized access and modification of order data, which may violate data integrity and confidentiality requirements in GDPR and HIPAA. Unauthorized confirmation of orders or altering return tracking details could expose sensitive customer information or disrupt compliance with audit trails and transaction records.

Mitigation Strategies

Immediately update CoreShop to a patched version beyond 1.5.5. If an update is unavailable, implement strict input validation for orderId and reshipId parameters in OrderConfirm and SendReship endpoints. Enforce ownership checks by binding operations to the authenticated user's ID (_user.ID) and validate that the user owns the order before processing requests.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-108696. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart