A vulnerability, which was classified as problematic , has been found in Webkul Bagisto up to 2.4.4 . Affected is an unknown function of the file /admin/customers/login-as-customer/ of the component Admin Customer Impersonation Feature . This manipulation of the argument ID causes authorization bypass. This vulnerability is handled as CVE-2026-19834 . The attack can be initiated remotely. Additionally, an exploit exists. The vendor confirms: "The reported issues were already identified through o