PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-49775 info@welcart CVE debrief

CVE-2026-49775 is a MEDIUM severity vulnerability (CVSS Score: 6.5) in Welcart e-Commerce versions <= 2.11.28. The vulnerability is caused by Unauthenticated Broken Access Control. It was published on 2026-06-15T21:17:22.290Z and last modified on 2026-06-15T21:24:32.790Z.

Vendor
info@welcart
Product
Welcart e-Commerce
CVSS
MEDIUM 6.5
CISA KEV
Not listed in stored evidence
Original CVE published
2026-06-15
Original CVE updated
2026-06-15
Advisory published
2026-06-15
Advisory updated
2026-06-15

Who should care

Users of Welcart e-Commerce versions <= 2.11.28 should apply patches or mitigations as available.

Technical summary

CVE-2026-49775 is a MEDIUM severity vulnerability (CVSS Score: 6.5) in Welcart e-Commerce versions <= 2.11.28. The vulnerability is caused by Unauthenticated Broken Access Control, with a CVSS vector of CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L. The weakness is classified as CWE-862.

Defensive priority

MEDIUM

Recommended defensive actions

  • Apply patches or mitigations as available for Welcart e-Commerce versions <= 2.11.28.
  • Review and update Welcart e-Commerce to a version greater than 2.11.28.

Evidence notes

Evidence from Patchstack indicates a vulnerability in Welcart e-Commerce versions <= 2.11.28.

Official resources

CVE-2026-49775 was published on 2026-06-15T21:17:22.290Z and last modified on 2026-06-15T21:24:32.790Z.