THREAT OPS › Threat News › [GHSA] GHSA-f7h9-qv4x-9x57 (medium) — Shopping privilege escalation through missing authorization in Settings components
[GHSA] GHSA-f7h9-qv4x-9x57 (medium) — Shopping privilege escalation through missing authorization in Settings components
GHSA-f7h9-qv4x-9x57 Severity: medium CVE: CVE-2026-56826
Shopping privilege escalation through missing authorization in Settings components
## Summary
Four Livewire components in the Settings area expose destructive Filament actions (`delete` / `edit`) that perform **no server-side authorization**. Any authenticated user who can reach the Settings pages — i.e. holding only the coarse `access_se
Indicators of compromise
- CVE-2026-56826cve
Original source: https://github.com/advisories/GHSA-f7h9-qv4x-9x57