PatchSiren cyber security CVE debrief
CVE-2026-79410 Webkul CVE debrief
CVE-2026-79410 is a high-severity vulnerability in Webkul Bagisto v2.4.9, allowing authenticated attackers to manipulate order totals by exploiting improper validation of the quantity parameter in the add-to-cart path. This could lead to potential unauthorized modifications to order totals, possible financial impacts, and reputational damage. Defenders and administrators should assess exposure, prioritize patching, and monitor for potential unauthorized order modifications to prevent financial and reputational impacts. The CVE record and NVD entry provide details on this vulnerability, emphasizing the need for verification and patching of Webkul Bagisto v2.4.9. Affected product or
- Vendor
- Webkul
- Product
- Bagisto
- CVSS
- HIGH 8.1
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-09-15
- Original CVE updated
- 2026-09-22
- Advisory published
- 2026-09-15
- Advisory updated
- 2026-09-22
Who should care
Defenders and administrators of Webkul Bagisto v2.4.9 deployments should assess exposure and prioritize patching to prevent potential unauthorized order modifications.
Why it matters
CVE-2026-79410 is a high-severity vulnerability in Webkul Bagisto v2.4.9 that allows authenticated attackers to manipulate order totals. Defenders and administrators should assess exposure, prioritize patching, and monitor for potential unauthorized order modifications to prevent financial and reputational impacts.
- Potential unauthorized modifications to order totals
- Possible financial impact due to manipulated order totals
- Need for verification and patching of Webkul Bagisto v2.4.9
- Potential reputational damage due to security incident
Technical summary
The CVE record and NVD entry describe an improper validation vulnerability in Webkul Bagisto v2.4.9, allowing authenticated attackers to reduce order totals by manipulating the quantity parameter in the add-to-cart path. This vulnerability has a CVSS score of 8.1 and is classified as HIGH severity. The vulnerability affects Webkul Bagisto v2.4.9 and could allow attackers to manipulate order totals, potentially leading to financial and reputational impacts. Defenders should prioritize verifying and applying patches for Webkul Bagisto v2.4.9, assessing exposure in
Defensive priority
Defenders should prioritize verifying and applying patches for Webkul Bagisto v2.4.9, assessing exposure in their environments, and monitoring for potential unauthorized order modifications.
Recommended defensive actions
- Verify and apply patches for Webkul Bagisto v2.4.9
- Assess exposure in environments using Webkul Bagisto
- Monitor for potential unauthorized order modifications
Evidence notes
The CVE record and NVD entry provide details on the improper validation of the quantity parameter in Webkul Bagisto v2.4.9, allowing authenticated attackers to manipulate order totals.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-79410 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-79410
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-79410 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-79410
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://github.com/isukasanuj/bagisto-cve/blob/main/CVE-2026-79410.md
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.