CVE Explorer
CVE-2026-21446
Bagisto is an open source laravel eCommerce platform. In versions on the 2.3 branch prior to 2.3.10, API routes remain active even after initial installation is complete. The underlying API endpoints (`/install/api/*`) are directly accessible and exploitable without any authentication. An attacker can bypass the Ib installer entirely by calling the API endpoints directly. This allows any unauthenticated attacker to create admin accounts, modify application configurations, and potentially overwri
Known exploited
Not asserted
Disputed
No
Stale source
No
Conflicts
0
Affected products and versions
1 source assertion{"product":"bagisto","vendor":"bagisto","versions":[{"status":"affected","version":">= 2.3.0, < 2.3.10"}]}
- cve_program_cvelist_v5affectedurn:baitaphish:normalized-source-record:v2:48aebe6345f7844afb990e3716302e8cac9b702f66a13ff4dce1e6e772954b23 · sha256:4d9fc03261c31d52… · /containers/cna/affected/0
Provider-owned CVSS observations
1 source assertion{"metric":{"attackComplexity":"LOW","attackRequirements":"NONE","attackVector":"NETWORK","baseScore":8.8,"baseSeverity":"HIGH","privilegesRequired":"NONE","subAvailabilityImpact":"NONE","subConfidentialityImpact":"NONE","subIntegrityImpact":"NONE","userInteraction":"NONE","vectorString":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:P","version":"4.0","vulnAvailabilityImpact":"NONE","vulnConfidentialityImpact":"HIGH","vulnIntegrityImpact":"HIGH"},"metric_type":"cvssV4_0"}
- cve_program_cvelist_v5cvssurn:baitaphish:normalized-source-record:v2:48aebe6345f7844afb990e3716302e8cac9b702f66a13ff4dce1e6e772954b23 · sha256:4d9fc03261c31d52… · /containers/cna/metrics/0/cvssV4_0
CWE assertions
1 source assertion{"cweId":"CWE-306","description":"CWE-306: Missing Authentication for Critical Function","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:48aebe6345f7844afb990e3716302e8cac9b702f66a13ff4dce1e6e772954b23 · sha256:4d9fc03261c31d52… · /containers/cna/problemTypes/0/descriptions/0
Source references
2 source assertions{"name":"https://github.com/bagisto/bagisto/commit/380c045e48490da740cd505fb192cc45e1809bed","tags":["x_refsource_MISC"],"url":"https://github.com/bagisto/bagisto/commit/380c045e48490da740cd505fb192cc45e1809bed"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:48aebe6345f7844afb990e3716302e8cac9b702f66a13ff4dce1e6e772954b23 · sha256:4d9fc03261c31d52… · /containers/cna/references/1
{"name":"https://github.com/bagisto/bagisto/security/advisories/GHSA-6h7w-v2xr-mqvw","tags":["x_refsource_CONFIRM"],"url":"https://github.com/bagisto/bagisto/security/advisories/GHSA-6h7w-v2xr-mqvw"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:48aebe6345f7844afb990e3716302e8cac9b702f66a13ff4dce1e6e772954b23 · sha256:4d9fc03261c31d52… · /containers/cna/references/0
Attribution and limitations
- CVE Program CVEList V5: Reproduce the MITRE copyright designation and CVE license in copies. Source →
Provider severity values are preserved separately. Baitaphish does not convert them into a risk rating, infer affected products, or treat EPSS as observed exploitation.