{"id":"CVE-2026-101139","summary":"Webkul Bagisto Invoice Mass Status Update state authorization","details":"A vulnerability was detected in Webkul Bagisto up to 2.4.6/2.5.0-beta4. This impacts an unknown function of the file /admin/sales/invoices/mass-update/state of the component Invoice Mass Status Update. Performing a manipulation results in missing authorization. The attack can be initiated remotely. The exploit is now public and may be used. Upgrading to version 2.5.0-beta5 will fix this issue. The patch is named 2c34b94d0313824ce98efee8aef8ee141d9b89d0. It is recommended to apply a patch to fix this issue. The vendor confirms: \"[W]e run continuous automated AI-assisted security scanning across the Bagisto codebase. The behaviour you describe has already been identified and reproduced internally, and it is actively being fixed rather than triaged from scratch.\"","modified":"2026-09-30T03:47:03.632450274Z","published":"2026-09-28T19:00:11.265Z","database_specific":{"cna_assigner":"VulDB","cwe_ids":["CWE-862","CWE-863"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/101xxx/CVE-2026-101139.json"},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/101xxx/CVE-2026-101139.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-101139"},{"type":"ADVISORY","url":"https://vuldb.com/cve/CVE-2026-101139"},{"type":"ADVISORY","url":"https://vuldb.com/submit/894633"},{"type":"ADVISORY","url":"https://vuldb.com/vuln/410992"},{"type":"REPORT","url":"https://vuldb.com/vuln/410992/cti"},{"type":"FIX","url":"https://github.com/bagisto/bagisto/commit/2c34b94d0313824ce98efee8aef8ee141d9b89d0"},{"type":"FIX","url":"https://github.com/bagisto/bagisto/pull/11493"},{"type":"FIX","url":"https://github.com/bagisto/bagisto/releases/tag/v2.5.0-beta5"},{"type":"EVIDENCE","url":"https://drive.google.com/file/d/1ymuUIZJaHZ7oDyebyLKn9RfRPAzDKMmm/view"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/bagisto/bagisto","events":[{"introduced":"487533a8f8552b94c937722cc3109ae41afc7604"},{"last_affected":"b4662d8d1d96a88b46bd41afef2ef7b510038763"}],"database_specific":{"source":"AFFECTED_FIELD","extracted_events":[{"introduced":"2.4.0"},{"last_affected":"2.4.0"},{"introduced":"2.4.1"},{"last_affected":"2.4.1"},{"introduced":"2.4.2"},{"last_affected":"2.4.2"},{"introduced":"2.4.3"},{"last_affected":"2.4.3"},{"introduced":"2.4.4"},{"last_affected":"2.4.4"},{"introduced":"2.4.5"},{"last_affected":"2.4.5"},{"introduced":"2.4.6"},{"last_affected":"2.4.6"},{"introduced":"2.5.0-beta1"},{"last_affected":"2.5.0-beta1"},{"introduced":"2.5.0-beta2"},{"last_affected":"2.5.0-beta2"},{"introduced":"2.5.0-beta3"},{"last_affected":"2.5.0-beta3"},{"introduced":"2.5.0-beta4"},{"last_affected":"2.5.0-beta4"}]}}],"versions":["2.4.0","2.4.1","2.4.2","2.4.3","2.4.4","2.4.5","2.4.6","2.5.0-beta1","2.5.0-beta2","2.5.0-beta3","2.5.0-beta4","v2.5.0-beta4","v2.5.0-beta2","v2.5.0-beta1","v2.4.1","v2.4.0"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-101139.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:P"}]}