<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Thu, 08 Oct 2026 11:28:51 +0000</lastBuildDate>
    <item>
      <title>EUVD-2026-323042</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-323042</link>
      <description>EUVD-2026-323042</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-323042</guid>
    </item>
    <item>
      <title>fkie_cve-2026-47744</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-47744</link>
      <description>&lt;p&gt;Shopper is a Headless e-commerce Admin Panel. Prior to 2.8.0, two distinct authorization defects in the team settings allowed any authenticated panel user to take over the RBAC system. Settings/Team/Index had no mount() authorization. Any authenticated user could load the page and use its public actions to create new roles and delete other users, including administrators. Settings/Team/RolePermission gated its write actions on the read-only view_users permission. Any user holding view_users could grant themselves or any other user arbitrary permissions, including manage_users and edit_orders, effectively escalating to full panel administrator from a read-only account. Combined, these two defects allow a low-privilege authenticated user to obtain administrator privileges and remove the legitimate administrators from the panel. This vulnerability is fixed in 2.8.0.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Shopper is a Headless e-commerce Admin Panel. Prior to 2.8.0, two distinct authorization defects in the team settings allowed any authenticated panel user to take over the RBAC system. Settings/Team/Index had no mount() authorization. Any authenticated user could load the page and use its public actions to create new roles and delete other users, including administrators. Settings/Team/RolePermission gated its write actions on the read-only view_users permission. Any user holding view_users could grant themselves or any other user arbitrary permissions, including manage_users and edit_orders, effectively escalating to full panel administrator from a read-only account. Combined, these two defects allow a low-privilege authenticated user to obtain administrator privileges and remove the legitimate administrators from the panel. This vulnerability is fixed in 2.8.0.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-47744</guid>
    </item>
    <item>
      <title>GHSA-c3qp-2ggw-xjg7 — Shopper: Authorization bypass and RBAC privilege escalation in team settings</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-c3qp-2ggw-xjg7</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Packagist: shopper/framework&lt;/p&gt;
&lt;p&gt;## Impact&lt;/p&gt;
&lt;p&gt;Two distinct authorization defects in the team settings allowed any authenticated panel user to take over the RBAC system:&lt;/p&gt;
&lt;p&gt;- `Settings/Team/Index` had no `mount()` authorization. Any authenticated user could load the page and use its public actions to create new roles and delete other users, including administrators.
- `Settings/Team/RolePermission` gated its write actions on the read-only `view_users` permission. Any user holding `view_users` could grant themselves or any other user arbitrary permissions, including `manage_users` and `edit_orders`, effectively escalating to full panel administrator from a read-only account.&lt;/p&gt;
&lt;p&gt;Combined, these two defects allow a low-privilege authenticated user to obtain administrator privileges and remove the legitimate administrators from the panel.&lt;/p&gt;
&lt;p&gt;## Patches&lt;/p&gt;
&lt;p&gt;Fixed in `v2.8.0`:&lt;/p&gt;
&lt;p&gt;- `Settings/Team/Index::mount()` now authorizes against `manage_users`.
- `Settings/Team/RolePermission` write actions now require `manage_users` instead of `view_users`.&lt;/p&gt;
&lt;p&gt;Upgrade via:&lt;/p&gt;
&lt;p&gt;```bash
composer require shopper/admin:^2.8
```&lt;/p&gt;
&lt;p&gt;## Workarounds&lt;/p&gt;
&lt;p&gt;None. Upgrade to `v2.8.0`.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Packagist: shopper/framework&lt;/p&gt;
&lt;p&gt;## Impact&lt;/p&gt;
&lt;p&gt;Two distinct authorization defects in the team settings allowed any authenticated panel user to take over the RBAC system:&lt;/p&gt;
&lt;p&gt;- `Settings/Team/Index` had no `mount()` authorization. Any authenticated user could load the page and use its public actions to create new roles and delete other users, including administrators.
- `Settings/Team/RolePermission` gated its write actions on the read-only `view_users` permission. Any user holding `view_users` could grant themselves or any other user arbitrary permissions, including `manage_users` and `edit_orders`, effectively escalating to full panel administrator from a read-only account.&lt;/p&gt;
&lt;p&gt;Combined, these two defects allow a low-privilege authenticated user to obtain administrator privileges and remove the legitimate administrators from the panel.&lt;/p&gt;
&lt;p&gt;## Patches&lt;/p&gt;
&lt;p&gt;Fixed in `v2.8.0`:&lt;/p&gt;
&lt;p&gt;- `Settings/Team/Index::mount()` now authorizes against `manage_users`.
- `Settings/Team/RolePermission` write actions now require `manage_users` instead of `view_users`.&lt;/p&gt;
&lt;p&gt;Upgrade via:&lt;/p&gt;
&lt;p&gt;```bash
composer require shopper/admin:^2.8
```&lt;/p&gt;
&lt;p&gt;## Workarounds&lt;/p&gt;
&lt;p&gt;None. Upgrade to `v2.8.0`.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-c3qp-2ggw-xjg7</guid>
    </item>
  </channel>
</rss>
