Missing Authorization in PrestaShop - #VU144206
Published: August 18, 2026
Vulnerability details
The vulnerability allows a remote user to disclose customer and order information.
The vulnerability exists due to improper access control in the back-office notifications endpoint when handling requests for notification panel data. A remote user can send a request with a valid back-office session to disclose customer and order information.
The issue affects employee accounts whose profiles grant no permission at all, and anonymous visitors are not affected.