A critical security vulnerability, tracked as CVE-2026-72843, has been identified in the EverShop software, allowing unauthenticated account takeovers with a CVSS score of 9.3. This issue could enable attackers to steal customer profiles and change passwords without prior access. The vulnerability is linked to a public access misconfiguration in the customer update route, allowing any individual with a valid UUID to alter account details.
No confirmed instances of exploitation have been reported, but users are urged to update to version 2.2.1, which addresses the issue by changing the route access to private. The vulnerability poses significant risks to user privacy and can damage businesses' reputations. Immediate patching is recommended.