THREAT OPS › Threat News › [GHSA] GHSA-j328-xmgp-j4q3 (high) — Shopper: privilege escalation via improper Livewire admin component authorization
[GHSA] GHSA-j328-xmgp-j4q3 (high) — Shopper: privilege escalation via improper Livewire admin component authorization
GHSA-j328-xmgp-j4q3 Severity: high CVE: CVE-2026-56828
Shopper: privilege escalation via improper Livewire admin component authorization
## Summary
Three Livewire admin components in `shopper/framework` (latest master at commit `fcd0c59`, released as v2.8.0) gate state-mutating actions on the read-only `view_users` permission. This is the same class as the issue Shopper fixed in v2.8.0 / PR #51
Indicators of compromise
- fcd0c5920588702df5b874f432b1042abd77a50bsha1
- CVE-2026-56828cve
Original source: https://github.com/advisories/GHSA-j328-xmgp-j4q3