A vulnerability was found in Webkul Bagisto up to 2.4.4 . It has been classified as problematic . This vulnerability affects unknown code of the file /admin/reporting/sales/ of the component Backend Reporting Endpoint . The manipulation leads to authorization bypass. This vulnerability is referenced as CVE-2026-19838 . Remote exploitation of the attack is possible. Furthermore, an exploit is available. The vendor confirms: "The reported issues were already identified through our internal securit