# CVE-2026-56830

## Summary

- **CVE ID:** CVE-2026-56830
- **Severity:** MEDIUM
- **CVSS Score:** 6.5 (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N)
- **CWE:** CWE-862
- **Published:** Sep 15, 2026
- **Last Modified:** Sep 15, 2026

## Description

Shopper is a Headless e-commerce Admin Panel. Prior to 2.9.2, an earlier product sub-form hardening change left store() in packages/admin/src/Livewire/Components/Products/Form/Media.php without the edit_products authorization check used by sibling sub-forms. An authenticated staff user with browse_products can invoke the Livewire store action and replace the thumbnail and gallery images for a product whose Media component was initialized, even without product-edit permission. The product binding is locked, so the attacker cannot redirect the update to an arbitrary product through client-side ID substitution, and the impact is limited to products whose edit pages were loaded. This issue is fixed in version 2.9.2.

## Affected Products

- shopperlabs — shopper (< 2.9.2)

## References

- [CNA](https://github.com/shopperlabs/shopper/security/advisories/GHSA-99h5-jhh7-v3r3)
- [CNA](https://github.com/shopperlabs/shopper/pull/570)
- [CNA](https://github.com/shopperlabs/shopper/commit/bf72e2753e21296184596d507336c7d65ecd46ff)
- [CNA](https://github.com/shopperlabs/shopper/releases/tag/v2.9.2)

## Exploitation Prediction (EPSS)

- **EPSS Score:** 0.36%
- **EPSS Percentile:** 29.8

---
_Exported from OnDuty AI Vulnerability Intelligence on 2026-09-17._