CRITICAL
9.8 CVE-2026-72843 Published 20 Aug 2026
EverShop Customer Account Takeover
Worried this affects one of your servers?
EverShop's customer update route is publicly accessible, allowing unauthenticated users to change email addresses and passwords of other customers.
EverShop versions prior to 2.2.1 are affected. An attacker can exploit this to take over customer accounts.
Reference: CVE-2026-72843 on NVD
← Back to Security News