← العودة للجدول
CVE-2026-47744
CVE-2026-47744 — GHSA: Shopper: Authorization bypass and RBAC privilege escalation in team settings
📅 2026-06-05
🔴 Critical 🔥 No GHSA Exploit Supply Chain CVSS 9.9 🎯 EPSS 0.04%

📋 الوصف الكامل

## Impact Two distinct authorization defects in the team settings allowed any authenticated panel user to take over the RBAC system: - `Settings/Team/Index` had no `mount()` authorization. Any authenticated user could load the page and use its public actions to create new roles and delete other users, including administrators. - `Settings/Team/RolePermission` gated its write actions on the read-

💻 الأنظمة المتأثرة

GHSA: Shopper: Authorization

⚠️ نوع التهديد

Exploit

🔗 CVE ID

CVE-2026-47744

📡 المصدر

GHSA

✅ الحلول والتخفيف

🔗 المصدر الأصلي ← 📘 NVD ← ⚡ CISA KEV ←