CVE-2026-6744: Bagisto Downloadable Link copy server-side request forgery
A vulnerability was found in Bagisto up to 2.3.15. Affected is the function copy of the component Downloadable Link Handler. The manipulation results in server-side request forgery. The attack may be launched remotely. The exploit has been made public and could be used. The vendor was contacted early about this disclosure and explains: "We already replied on the github advisories. All the security issues are addressed through security advisory. We will fix this in our upcomming releases."
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-6744?
CVE-2026-6744 has a critical severity due to its potential for remote exploitation through server-side request forgery.
How do I fix CVE-2026-6744?
To fix CVE-2026-6744, update Bagisto to version 2.4.0 or later as it addresses this vulnerability.
Who is affected by CVE-2026-6744?
CVE-2026-6744 affects all versions of Bagisto up to and including 2.3.15.
What can an attacker do with CVE-2026-6744?
An attacker can exploit CVE-2026-6744 to perform server-side request forgery attacks, potentially leading to unauthorized access to internal resources.
Is CVE-2026-6744 remote exploitability?
Yes, CVE-2026-6744 can be exploited remotely without requiring local access to the affected system.