A vulnerability was found in Webkul Bagisto up to 2.4.4 and classified as problematic . This affects an unknown part of the file /admin/customers/search of the component Customer Search . Executing a manipulation of the argument Query can lead to information disclosure. The identification of this vulnerability is CVE-2026-19837 . The attack may be launched remotely. Furthermore, there is an exploit available. The vendor confirms: "The reported issues were already identified through our internal