SEPTEMBER 17, 2026
Live Feed
Back to database
Case File

CVE-2026-79409

MEDIUM · CVSS 6.5 EPSS 0.42% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-09-15 · Last synced 2026-09-17

CyberRota Analysis

AI-Generated

Webkul Bagisto version 2.4.9 is vulnerable to a remote information disclosure flaw that enables attackers to access sensitive data through the add-to-cart API and downloadable fulfillment components. This could lead to unauthorized exposure of user information or system details. E-commerce platforms utilizing this version should prioritize patching to mitigate potential data breaches.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

GitHub PoC Links

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-79409
Severity
MEDIUM
CVSS
6.5
EPSS
0.42%

Original NVD Description

An issue in Webkul Bagisto 2.4.9 allows a remote attacker to obtain sensitive information via the add-to-cart API and the downloadable fulfilment components.