THREATOPS
THREAT OPSThreat News › [GHSA] GHSA-f7h9-qv4x-9x57 (medium) — Shopping privilege escalation through missing authorization in Settings components

[GHSA] GHSA-f7h9-qv4x-9x57 (medium) — Shopping privilege escalation through missing authorization in Settings components

medgithub_advisoriesPublished 2026-09-11

GHSA-f7h9-qv4x-9x57 Severity: medium CVE: CVE-2026-56826

Shopping privilege escalation through missing authorization in Settings components

## Summary

Four Livewire components in the Settings area expose destructive Filament actions (`delete` / `edit`) that perform **no server-side authorization**. Any authenticated user who can reach the Settings pages — i.e. holding only the coarse `access_se

Indicators of compromise

Original source: https://github.com/advisories/GHSA-f7h9-qv4x-9x57