CVE-2026-72843
The customer update route in EverShop is declared with "access": "public" in packages/evershop/src/modules/customer/api/updateCustomer/route.json, which causes the admin authentication middleware to call next() without checking the caller, and no customer-session middleware guards the route; the only middleware in the chain parses the JSON body. The handler in updateCustomer.js then loads the customer by the uuid taken from the URL path and writes the supplied fields back to that record, hashing a password if one is provided, without verifying that the caller owns the record.
Leer descripción completaMostrar menos
An unauthenticated request carrying a known customer uuid can therefore overwrite that customer's email address and password and read back the updated record from the 200 response, taking over the account and locking out its owner. Customer uuids are exposed through order confirmation email links and administrative URLs. Version 2.2.1 changes the route to "access": "private".
CVSS
- Versión: 4.0
- Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
- Puntuación base: 9.3
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.84%
- Percentil entre todas las CVEs puntuadas: 56
- Fecha de la puntuación: 6/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
🎯 Técnicas ATT&CK
Cómo se explota esta vulnerabilidad y qué consigue el atacante, en el lenguaje de MITRE ATT&CK.
- Explotación
T1190Exploit Public-Facing Applicationinitial access95 % - Impacto principal
T1078Valid Accountsstealth · persistence · privilege escalation · initial access95 % - Impacto secundario
T1565.003Runtime Data Manipulationimpact85 %
Vulnerabilidad de acceso remoto sin autenticación (AV:N/PR:N/UI:N) en ruta API pública que permite sobrescribir credenciales y email ajenos, logrando takeover de cuenta sin verificar propiedad del UUID.
Inferido por nuestro agente de análisis a partir de la descripción oficial, el vector CVSS y la CWE, y comprobado por un supervisor. Puede contener errores.
🛡️ Mitigaciones ATT&CK que cubren estas técnicas
Tecnologías afectadas (1)
⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.
CWE
- CWE-862
Referencias
- https://github.com/evershopcommerce/evershop
- https://github.com/evershopcommerce/evershop/blob/v2.1.2/packages/evershop/src/modules/customer/api/updateCustomer/route.json
- https://github.com/evershopcommerce/evershop/blob/v2.1.2/packages/evershop/src/modules/customer/api/updateCustomer/updateCustomer.js
- https://github.com/evershopcommerce/evershop/issues/952
- https://github.com/evershopcommerce/evershop/releases/tag/v2.2.1
- https://www.vulncheck.com/advisories/evershop-missing-authorization-on-patch-api-customers-id-allows-unauthenticated-account-takeover
JSON original (NVD)
Mostrar
{
"id": "CVE-2026-72843",
"cveTags": [],
"metrics": {
"ssvcV203": [
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"ssvcData": {
"id": "CVE-2026-72843",
"role": "CISA Coordinator",
"options": [
{
"exploitation": "none"
},
{
"automatable": "yes"
},
{
"technicalImpact": "total"
}
],
"version": "2.0.3",
"timestamp": "2026-08-21T21:18:57.258144Z"
}
}
],
"cvssMetricV31": [
{
"type": "Secondary",
"source": "disclosure@vulncheck.com",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 9.8,
"attackVector": "NETWORK",
"baseSeverity": "CRITICAL",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
"integrityImpact": "HIGH",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "HIGH",
"privilegesRequired": "NONE",
"confidentialityImpact": "HIGH"
},
"impactScore": 5.9,
"exploitabilityScore": 3.9
}
],
"cvssMetricV40": [
{
"type": "Secondary",
"source": "disclosure@vulncheck.com",
"cvssData": {
"Safety": "NOT_DEFINED",
"version": "4.0",
"Recovery": "NOT_DEFINED",
"baseScore": 9.3,
"Automatable": "NOT_DEFINED",
"attackVector": "NETWORK",
"baseSeverity": "CRITICAL",
"valueDensity": "NOT_DEFINED",
"vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
"exploitMaturity": "NOT_DEFINED",
"providerUrgency": "NOT_DEFINED",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"attackRequirements": "NONE",
"privilegesRequired": "NONE",
"subIntegrityImpact": "NONE",
"vulnIntegrityImpact": "HIGH",
"integrityRequirement": "NOT_DEFINED",
"modifiedAttackVector": "NOT_DEFINED",
"subAvailabilityImpact": "NONE",
"vulnAvailabilityImpact": "HIGH",
"availabilityRequirement": "NOT_DEFINED",
"modifiedUserInteraction": "NOT_DEFINED",
"modifiedAttackComplexity": "NOT_DEFINED",
"subConfidentialityImpact": "NONE",
"vulnConfidentialityImpact": "HIGH",
"confidentialityRequirement": "NOT_DEFINED",
"modifiedAttackRequirements": "NOT_DEFINED",
"modifiedPrivilegesRequired": "NOT_DEFINED",
"modifiedSubIntegrityImpact": "NOT_DEFINED",
"modifiedVulnIntegrityImpact": "NOT_DEFINED",
"vulnerabilityResponseEffort": "NOT_DEFINED",
"modifiedSubAvailabilityImpact": "NOT_DEFINED",
"modifiedVulnAvailabilityImpact": "NOT_DEFINED",
"modifiedSubConfidentialityImpact": "NOT_DEFINED",
"modifiedVulnConfidentialityImpact": "NOT_DEFINED"
}
}
]
},
"affected": [
{
"source": "disclosure@vulncheck.com",
"affectedData": [
{
"repo": "https://github.com/evershopcommerce/evershop",
"vendor": "evershopcommerce",
"product": "evershop",
"versions": [
{
"status": "affected",
"version": "0",
"lessThan": "2.2.1",
"versionType": "semver"
},
{
"status": "unaffected",
"version": "2.2.1",
"versionType": "semver"
}
],
"packageURL": "pkg:npm/evershop",
"programFiles": [
"packages/evershop/src/modules/customer/api/updateCustomer/route.json",
"packages/evershop/src/modules/customer/api/updateCustomer/updateCustomer.js"
],
"defaultStatus": "unaffected"
}
]
}
],
"published": "2026-08-20T22:18:05.253",
"references": [
{
"url": "https://github.com/evershopcommerce/evershop",
"source": "disclosure@vulncheck.com"
},
{
"url": "https://github.com/evershopcommerce/evershop/blob/v2.1.2/packages/evershop/src/modules/customer/api/updateCustomer/route.json",
"source": "disclosure@vulncheck.com"
},
{
"url": "https://github.com/evershopcommerce/evershop/blob/v2.1.2/packages/evershop/src/modules/customer/api/updateCustomer/updateCustomer.js",
"source": "disclosure@vulncheck.com"
},
{
"url": "https://github.com/evershopcommerce/evershop/issues/952",
"source": "disclosure@vulncheck.com"
},
{
"url": "https://github.com/evershopcommerce/evershop/releases/tag/v2.2.1",
"source": "disclosure@vulncheck.com"
},
{
"url": "https://www.vulncheck.com/advisories/evershop-missing-authorization-on-patch-api-customers-id-allows-unauthenticated-account-takeover",
"source": "disclosure@vulncheck.com"
}
],
"vulnStatus": "Deferred",
"weaknesses": [
{
"type": "Secondary",
"source": "disclosure@vulncheck.com",
"description": [
{
"lang": "en",
"value": "CWE-862"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "The customer update route in EverShop is declared with \"access\": \"public\" in packages/evershop/src/modules/customer/api/updateCustomer/route.json, which causes the admin authentication middleware to call next() without checking the caller, and no customer-session middleware guards the route; the only middleware in the chain parses the JSON body. The handler in updateCustomer.js then loads the customer by the uuid taken from the URL path and writes the supplied fields back to that record, hashing a password if one is provided, without verifying that the caller owns the record. An unauthenticated request carrying a known customer uuid can therefore overwrite that customer's email address and password and read back the updated record from the 200 response, taking over the account and locking out its owner. Customer uuids are exposed through order confirmation email links and administrative URLs. Version 2.2.1 changes the route to \"access\": \"private\"."
}
],
"lastModified": "2026-09-24T20:43:32.537",
"sourceIdentifier": "disclosure@vulncheck.com"
}