CVE-2026-72843 | evershopcommerce EverShop up to 2.2.0 Customer updateCustomer.js uuid authorization
A vulnerability categorized as critical has been discovered in evershopcommerce EverShop up to 2.2.0. This vulnerability affects unknown code of the file updateCustomer.js of the component Customer. Such manipulation of the argument uuid leads to authorization bypass.
This vulnerability is listed as CVE-2026-72843. The attack may be performed from remote. There is no available exploit.
It is advisable to upgrade the affected component.VulDB Recent EntriesRead More