Missing Authorization in PrestaShop - #VU144206

 

Missing Authorization in PrestaShop - #VU144206

Published: August 18, 2026


Vulnerability identifier: #VU144206
CSH Severity: Low
CVSS v4: 5.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: N/A
CWE-ID: CWE-862
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to disclose customer and order information.

The vulnerability exists due to improper access control in the back-office notifications endpoint when handling requests for notification panel data. A remote user can send a request with a valid back-office session to disclose customer and order information.

The issue affects employee accounts whose profiles grant no permission at all, and anonymous visitors are not affected.


Affected software

PrestaShop

Remediation

Install security update from vendor's website.

PrestaShop - addressed in versions 8.2.8, 9.1.5

External References

Related Security Bulletins