Medium severity4.3NVD Advisory· Published Oct 11, 2026
CVE-2026-108696
CVE-2026-108696
Description
CoreShop through 1.5.5 contains an authorization bypass vulnerability in the OrderController that allows authenticated customers to act on other customers' orders by supplying user-controlled ids. Attackers can omit the data field in OrderConfirm or supply another reshipId to SendReship to confirm receipt of others' orders and overwrite return tracking details.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
1Patches
Vulnerability mechanics
References
5- github.com/CoreUnion/CoreShop/blob/ca7408b025bc5f3fd5957a79618ffe991c4e91ab/CoreCms.Net.Services/Order/CoreCmsOrderServices.csnvd
- github.com/CoreUnion/CoreShop/blob/ca7408b025bc5f3fd5957a79618ffe991c4e91ab/CoreCms.Net.Web.WebApi/Controllers/OrderController.csnvd
- github.com/CoreUnion/CoreShop/blob/ca7408b025bc5f3fd5957a79618ffe991c4e91ab/CoreCms.Net.Web.WebApi/Controllers/OrderController.csnvd
- hackmd.io/@1ExmmukzRMWN7B4gQ4W-4Q/SkVjopPsGenvd
- www.vulncheck.com/advisories/coreshop-through-1.5.5-authorization-bypass-via-ordercontroller-orderconfirm-and-sendreshipnvd
News mentions
0No linked articles in our index yet.