CVE-2026-39079: Infoleak
Published May 18, 2026
·Updated
An issue in prestashop upsshipping all versions through at least 2.4.0 allows a remote attacker to obtain sensitive information via the /modules/upsshipping/logs/, and /modules/upsshipping/lib/UPSBaseApi.php components
Affected Software
1 affected component
Prestashop upsshipping (PrestaShop module)<=2.4.0
Event History
May 18, 2026
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·03:16 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2026-39079?
CVE-2026-39079 has a severity rating of high with a CVSS score of 7.5.
2
How do I fix CVE-2026-39079?
To fix CVE-2026-39079, update the Prestashop upsshipping module to the latest version.
3
What kind of information is exposed due to CVE-2026-39079?
CVE-2026-39079 allows a remote attacker to access sensitive information via specific components of the upsshipping module.
4
Which versions of the Prestashop upsshipping module are affected by CVE-2026-39079?
CVE-2026-39079 affects all versions of the Prestashop upsshipping module through at least 2.4.0.
5
Is there a workaround for CVE-2026-39079 before applying a patch?
While the best solution is to update, a possible workaround for CVE-2026-39079 is to restrict access to the affected module components.