CVE-2026-39079
7.5PrestaShop · upsshipping
A vulnerability exists in the PrestaShop upsshipping module that may allow unauthorized access to sensitive information.
Executive summary
A potential information disclosure vulnerability in the PrestaShop upsshipping module poses a risk of unauthorized data exposure to unauthenticated attackers.
Vulnerability
The vulnerability is an unauthenticated access issue, allowing remote attackers to potentially retrieve sensitive data without requiring prior login or high-level privileges.
Business impact
Successful exploitation could lead to the unauthorized disclosure of sensitive business or customer information managed by the PrestaShop platform. While the CVSS score of 7.5 indicates a High severity, the impact is focused on data confidentiality, which could lead to significant regulatory or reputational damage.
Remediation
Immediate Action: Consult the vendor advisory at https://labs.esokia.com/cve/cve-2026-39079/ for specific patch availability and update instructions.
Proactive Monitoring: Monitor web server access logs for anomalous, high-frequency requests targeting module-specific directories or parameters.
Compensating Controls: Implement a Web Application Firewall (WAF) rule to block suspicious traffic patterns directed at the affected module's URI.
Exploitation status
Public Exploit Available: Unknown
Analyst recommendation
Given the availability of a proof-of-concept and the potential for unauthenticated access, administrators should treat this vulnerability with urgency. Prioritize reviewing the vendor's guidance and apply any available security updates or module patches immediately to prevent unauthorized data access.