THREATOPS
THREAT OPSThreat News › [GHSA] GHSA-243p-f3cv-c5wh (high) — Shopper: Authorization bypass in Filament bulk actions allows browse-only staff to mass-delete attributes/tags and mass-toggle visibility of brands/categories/suppliers

[GHSA] GHSA-243p-f3cv-c5wh (high) — Shopper: Authorization bypass in Filament bulk actions allows browse-only staff to mass-delete attributes/tags and mass-toggle visibility of brands/categories/suppliers

medgithub_advisoriesPublished 2026-09-11

GHSA-243p-f3cv-c5wh Severity: high CVE: CVE-2026-56827

Shopper: Authorization bypass in Filament bulk actions allows browse-only staff to mass-delete attributes/tags and mass-toggle visibility of brands/categories/suppliers

## Summary

Five Filament `groupedBulkActions` blocks across the Shopper admin Livewire pages omit the `->authorize(...)` permission gate, while their per-record sibling acti

Indicators of compromise

Original source: https://github.com/advisories/GHSA-243p-f3cv-c5wh