securityonline.info 8/23/2026, 9:02:35 AM · external

EverShop vulnerability lets attackers seize accounts via UUID

EverShop vulnerability lets attackers seize accounts via UUID
CyberSIXT Evidence Panel
Primary Source github.com
CVE Intel
CISA KEV Not in KEV
Patch Patch Available

A critical security vulnerability, tracked as CVE-2026-72843, has been identified in the EverShop software, allowing unauthenticated account takeovers with a CVSS score of 9.3. This issue could enable attackers to steal customer profiles and change passwords without prior access. The vulnerability is linked to a public access misconfiguration in the customer update route, allowing any individual with a valid UUID to alter account details.

No confirmed instances of exploitation have been reported, but users are urged to update to version 2.2.1, which addresses the issue by changing the route access to private. The vulnerability poses significant risks to user privacy and can damage businesses' reputations. Immediate patching is recommended.

View Primary Source Via securityonline.info

Article by CyberSIXT