CVE-2026-101139 | Webkul Bagisto up to 2.4.6 Invoice Mass Status Update state authorization

SecurityVulns

A vulnerability was found in Webkul Bagisto up to 2.4.6. It has been rated as problematic. This impacts an unknown function of the file /admin/sales/invoices/mass-update/state of the component Invoice Mass Status Update. Performing a manipulation results in missing authorization.

This vulnerability is identified as CVE-2026-101139. The attack can be initiated remotely. Additionally, an exploit exists.

The vendor was contacted early about this disclosure.VulDB Recent EntriesRead More