CVE-2026-19993: Webkul Bagisto RMA State Validation update-status behavioral workflow
A vulnerability has been found in Webkul Bagisto up to 2.4.4. Affected by this vulnerability is an unknown functionality of the file /customer/account/rma/update-status of the component RMA State Validation. The manipulation leads to enforcement of behavioral workflow. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The vendor confirms: "The reported issues were already identified through our internal security assessment process prior to this notification and are being handled through our established internal security and development lifecycle. Some of these items have already been addressed, while the remaining items are planned for resolution in upcoming product releases."
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-19993?
CVE-2026-19993 has a medium severity score of 4.3.
How do I fix CVE-2026-19993?
To fix CVE-2026-19993, update Webkul Bagisto to version 2.4.5 or later.
What component is affected by CVE-2026-19993?
CVE-2026-19993 affects the RMA State Validation component of Webkul Bagisto.
What type of vulnerability is CVE-2026-19993?
CVE-2026-19993 is a behavioral workflow enforcement vulnerability in Webkul Bagisto.
What impact does CVE-2026-19993 have?
CVE-2026-19993 allows for manipulation related to the behavioral workflow in the affected application.