CVE-2026-72843Patch

LOWCVSS 9.3 · CRITICAL

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Patch affected systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

The customer update route in EverShop is declared with "access": "public" in packages/evershop/src/modules/customer/api/updateCustomer/route.json, which causes the admin authentication middleware to call next() without checking the caller, and no customer-session middleware guards the route; the only middleware in the chain parses the JSON body. The handler in updateCustomer.js then loads the customer by the uuid taken from the URL path and writes the supplied fields back to that record, hashing a password if one is provided, without verifying that the caller owns the record. An unauthenticated request carrying a known customer uuid can therefore overwrite that customer's email address and password and read back the updated record from the 200 response, taking over the account and locking out its owner. Customer uuids are exposed through order confirmation email links and administrative URLs. Version 2.2.1 changes the route to "access": "private".

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-862

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Patch or workaround signal is available
  • 3 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 2 signals
  • Disclosure: 1 classified signal
  • Peaked at 2 mentions on most recent observed day (2026-08-23)
  • 3 total mentions across 2 days

Deep dive

Activity timeline3 mentions / 2d
01122Mentions · 2026-08-21: 1Mentions · 2026-08-23: 2Patch / Workaround · 2026-08-23: 2Technical Details · 2026-08-21: 1Technical Details · 2026-08-23: 108-2108-23
Signal classification2 categories
Patch
266.7%
Disclosure
133.3%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-08-211
Disclosure1
2026-08-232
Patch2
Full discourse3 posts
  • Daily CyberSecurity@Daily_CyberSec
    Patch

    A critical EverShop account takeover flaw, CVE-2026-72843, exposes systems to an eCommerce platform vulnerability. Update to version 2.2.1 immediately. #EverShop #CyberSecurity #CVE202672843 #Vulnerability #eCommerce http://securityonline.info/evershop-cve-2026-72843-account-takeover/

    Post summary

    CVE‑2026‑72843, an account takeover flaw in EverShop, is disclosed and users are urged to apply the patch by updating to version 2.2.1.

    01040581
    13.0K followersView on X
  • ransomNews@ransomnews
    Patch

    🚨 🔃 EverShop flaw enables account takeover CVE-2026-72843 lets attackers overwrite customer email and passwords using an exposed UUID; fixed in 2.2.1. 🔗 read more: https://securityonline.info/evershop-cve-2026-72843-account-takeover/?utm_source=twitter&utm_medium=social&utm_campaign=fedica-Calendario-Editoriale #ransomNews #cyberthreats #ecommerce

    Post summary

    The message announces the EverShop CVE‑2026‑72843, outlining how it allows account takeover and noting the vendor fix in version 2.2.1.

    00020306
    3.6K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-72843 EverShop Account Takeover Via Unauthenticated Customer Update Route https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-72843

    Post summary

    The content announces CVE-2026-72843 as an account takeover flaw in EverShop, describing the unauthenticated update route, but offers no PoC, exploit, patch, or evidence of active exploitation.

    00000108
    4.1K followersView on X

Explore more