Vulnerability Description
Shopper is a Headless e-commerce Admin Panel. Prior to 2.8.0, Multiple Filament actions on the admin Order detail and Order shipments table were callable by an authenticated low-privilege user without the permission required to mutate orders. The order detail actions cancel, mark paid, mark complete, capture payment, archive, and start processing were callable with the read-only read_orders permission and did not require edit_orders. capturePayment could trigger an actual PSP capture (real funds movement). The order shipments table actions mark delivered and edit tracking were callable with the read-only browse_orders permission. A user with read access to orders could therefore alter the lifecycle of every order in the panel and trigger real-world payment captures. This vulnerability is fixed in 2.8.0.
CVSS Score
HIGH
Related Weaknesses (CWE)
References
- https://github.com/shopperlabs/shopper/pull/511
- https://github.com/shopperlabs/shopper/security/advisories/GHSA-f946-9qp6-vgch
FAQ
What is CVE-2026-47740?
CVE-2026-47740 is a vulnerability with a CVSS score of 8.1 (HIGH). Shopper is a Headless e-commerce Admin Panel. Prior to 2.8.0, Multiple Filament actions on the admin Order detail and Order shipments table were callable by an authenticated low-privilege user without...
How severe is CVE-2026-47740?
CVE-2026-47740 has been rated HIGH with a CVSS base score of 8.1/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2026-47740?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.