CRITICAL
evershopcommerce
CVE published 2026-08-20
CVE-2026-72843
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-20T22:18:05.253Z and has not been modified since then. The customer update route in EverShop was declared with public access, lacking authentication and session management. This allowed unauthenticated attackers to overwrite customer email addresses and passwords, effectively taking over accounts. T [truncated]