THREAT OPS › Threat News › [GHSA] GHSA-2cg9-97gq-9mqp (high) — Shopper: Missing authorization on product removal actions in CollectionProducts component
[GHSA] GHSA-2cg9-97gq-9mqp (high) — Shopper: Missing authorization on product removal actions in CollectionProducts component
GHSA-2cg9-97gq-9mqp Severity: high CVE: CVE-2026-56825
Shopper: Missing authorization on product removal actions in CollectionProducts component
## Title
Missing authorization on product removal actions in CollectionProducts component
## Description
A lack of authorization control was discovered on both the per-record delete action and the bulk delete action inside `packages/admin/src/Livewir
Indicators of compromise
- CVE-2026-56825cve
Original source: https://github.com/advisories/GHSA-2cg9-97gq-9mqp