CVE-2026-39079

7.5

PrestaShop · upsshipping

A vulnerability exists in the PrestaShop upsshipping module that may allow unauthorized access to sensitive information.

Executive summary

A potential information disclosure vulnerability in the PrestaShop upsshipping module poses a risk of unauthorized data exposure to unauthenticated attackers.

Vulnerability

The vulnerability is an unauthenticated access issue, allowing remote attackers to potentially retrieve sensitive data without requiring prior login or high-level privileges.

Business impact

Successful exploitation could lead to the unauthorized disclosure of sensitive business or customer information managed by the PrestaShop platform. While the CVSS score of 7.5 indicates a High severity, the impact is focused on data confidentiality, which could lead to significant regulatory or reputational damage.

Remediation

Immediate Action: Consult the vendor advisory at https://labs.esokia.com/cve/cve-2026-39079/ for specific patch availability and update instructions.

Proactive Monitoring: Monitor web server access logs for anomalous, high-frequency requests targeting module-specific directories or parameters.

Compensating Controls: Implement a Web Application Firewall (WAF) rule to block suspicious traffic patterns directed at the affected module's URI.

Exploitation status

Public Exploit Available: Unknown

Analyst recommendation

Given the availability of a proof-of-concept and the potential for unauthenticated access, administrators should treat this vulnerability with urgency. Prioritize reviewing the vendor's guidance and apply any available security updates or module patches immediately to prevent unauthorized data access.

More PrestaShop CVEs