{"id":"CVE-2026-56829","title":"Shopper is a Headless e-commerce Admin Panel","summary":"Shopper is a Headless e-commerce Admin Panel. Prior to 2.9.2, packages/admin/src/Livewire/Components/Products/VariantStock.php exposes stockAction() without edit_product_variants authorization and leaves public $variant client mutable be…","severity":"high","cvss":8.1,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H","cwe":["CWE-862"],"vendor":"shopperlabs","product":"shopper","affected":["shopper < 2.9.2"],"patched":["shopper/framework 2.9.2"],"published":"2026-09-15","updated":"2026-09-15","sourceUpdated":"2026-09-15T19:17:23.530","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-56829","references":[{"url":"https://github.com/shopperlabs/shopper/commit/bf72e2753e21296184596d507336c7d65ecd46ff","label":"security-advisories@github.com"},{"url":"https://github.com/shopperlabs/shopper/pull/570","label":"security-advisories@github.com"},{"url":"https://github.com/shopperlabs/shopper/releases/tag/v2.9.2","label":"security-advisories@github.com"},{"url":"https://github.com/shopperlabs/shopper/security/advisories/GHSA-g3f9-g5vj-p62f","label":"security-advisories@github.com"},{"url":"https://github.com/shopperlabs/shopper/security/advisories/GHSA-g3f9-g5vj-p62f","label":"134c704f-9b21-4f2e-91b3-4a467353bcc0"},{"url":"https://github.com/advisories/GHSA-g3f9-g5vj-p62f"}],"tags":["nvd","cve.org","exploit-available","ghsa","composer"],"exploitAvailable":true,"ssvc":{"exploitation":"poc","automatable":"no","technicalImpact":"partial","timestamp":"2026-09-15T19:04:25.446927Z"},"aliases":["GHSA-g3f9-g5vj-p62f"],"ecosystem":"composer","ingestedAt":"2026-09-12T00:03:49.069Z","epss":0.0047,"epssPercentile":0.39705,"slug":"CVE-2026-56829","body":"## Overview\n\nShopper is a Headless e-commerce Admin Panel. Prior to 2.9.2, packages/admin/src/Livewire/Components/Products/VariantStock.php exposes stockAction() without edit_product_variants authorization and leaves public $variant client mutable because it lacks the Livewire Locked attribute. Any authenticated admin-panel user, including staff with only browse_products, can select an arbitrary product variant and inventory location through component state, then submit a positive or negative quantity adjustment. This permits browse-only staff to inflate stock, reduce stock, or force out-of-stock states for variants outside the current page. This issue is fixed in version 2.9.2.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.\n\n## Package advisory (CVE-2026-56829)\n\nAffected packages:\n\n- `shopper/framework < 2.9.2`\n\nPatched in:\n\n- `shopper/framework 2.9.2`\n\nSource: https://github.com/advisories/GHSA-g3f9-g5vj-p62f","depth":"midnight","depthScore":57,"depthScoreParts":{"impact":44.6,"likelihood":0.1,"exploitation":12,"ransomware":0},"changes":[{"seq":204491,"id":"CVE-2026-56829","ts":1789501416908,"field":"exploit_available","old":"false","new":"true"}]}