CVE-2026-57760: Missing Authorization in Sendcloud Shipping Access Controls
Sendcloud Shipping contains a missing authorization flaw that allows attackers to manipulate access control settings. Because the vulnerability lacks proper permission checks, an unauthenticated attacker can modify authorization levels without needing valid credentials or user interaction. This could enable unauthorized changes to shipping configurations or access permissions within affected installations.
Source data · NVD / CISA · public domain
- CVSS
- 3.1 · 5.3 MEDIUM · CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
- Weaknesses (CWE)
- CWE-862
- Affected products
- 0 configuration(s)
- Published / Modified
- 2026-07-02 / 2026-07-02
NVD description (verbatim)
Missing Authorization vulnerability in Sendcloud Sendcloud Shipping allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Sendcloud Shipping: from n/a through 1.0.29.
1 reference(s) · View on NVD →
SEC.co analysis · AI-assisted, reviewed against source
Technical summary
CVE-2026-57760 is a Missing Authorization vulnerability (CWE-862) in Sendcloud Shipping affecting versions through 1.0.29. The flaw stems from incorrectly configured access control security levels that fail to enforce proper authorization checks. The CVSS 3.1 score of 5.3 (MEDIUM) reflects a network-accessible attack vector requiring no privileges or user interaction, with integrity impact but no confidentiality or availability loss. The absence of authentication requirements means the vulnerability can be exploited by remote unauthenticated actors.
Business impact
A successful exploitation could allow attackers to modify shipping access controls, potentially disrupting order fulfillment workflows, altering shipping permissions for users, or creating privilege escalation paths within the platform. Organizations relying on Sendcloud Shipping for order management face risk of unauthorized configuration changes that could go undetected until discovered through audit or operational anomalies. The integrity impact could compromise the trustworthiness of shipping permissions and audit trails.
Affected systems
Sendcloud Shipping versions from an unspecified baseline through version 1.0.29 are vulnerable. Organizations using any version up to and including 1.0.29 should prioritize assessment. Verify your installed version in the Sendcloud admin panel or deployment logs to confirm exposure.
Exploitability
The vulnerability is relatively straightforward to exploit due to the absence of authentication barriers. No privileges, special network position, or user interaction is required—an attacker with network access can attempt to modify access control settings directly. However, the vulnerability is not currently listed on CISA's Known Exploited Vulnerabilities (KEV) catalog, suggesting active exploitation in the wild has not been formally documented at this time.
Remediation
Upgrade Sendcloud Shipping to a version that addresses the missing authorization controls. Contact Sendcloud support or consult their security advisories to identify the patched version. Until a patch is deployed, restrict network access to Sendcloud Shipping instances to trusted networks, disable remote administrative interfaces if not required, and enforce strict network segmentation around your shipping infrastructure.
Patch guidance
Sendcloud should have released a security update addressing CWE-862. Verify the availability of patched versions by consulting the official Sendcloud security advisory or release notes. Apply patches in a controlled manner—test in a non-production environment first to ensure compatibility with your order management workflows. Prioritize patching if you expose Sendcloud Shipping to untrusted networks or the broader internet.
Detection guidance
Monitor Sendcloud Shipping access control logs for unauthorized modifications to permission settings, user role assignments, or administrative configurations. Look for API calls or administrative actions originating from unexpected IP addresses or without corresponding user login sessions. Alert on any changes to authorization levels that do not correlate with legitimate administrative activity. Network IDS/IPS signatures may detect unusual access patterns to Sendcloud administrative endpoints if the attacker probes access control boundaries.
Why prioritize this
Although the CVSS score is MEDIUM (5.3), the absence of authentication requirements and the direct integrity impact on access controls warrant prompt attention. Shipping and fulfillment operations are often critical to revenue, and unauthorized access control changes could silently compromise operational trust. However, the lack of KEV designation and absence of confidentiality or availability impact place this below critical business-risk vulnerabilities. Prioritize patching for internet-facing Sendcloud instances and those handling high-value orders.
Risk score, explained
The CVSS 3.1 score of 5.3 reflects: Network-accessible attack surface (AV:N), low attack complexity (AC:L), no privilege or authentication requirement (PR:N/UI:N), single security domain scope (S:U), no confidentiality loss (C:N), integrity impact (I:L), and no availability loss (A:N). This is a moderate risk that should not be neglected but ranks below vulnerabilities affecting confidentiality, availability, or requiring authentication bypass to critical systems.
Frequently asked questions
Do we need to patch immediately if we run Sendcloud Shipping on an internal network only?
Internal-only deployment reduces immediate risk since the vulnerability requires network access. However, patch as soon as feasible because insider threats, compromised internal credentials, or lateral movement from other breaches could still enable exploitation. Do not use internal-only status as justification for indefinite deferral.
What should we look for to detect if this vulnerability has been exploited?
Audit Sendcloud Shipping logs for unauthorized changes to user roles, permission sets, or access control configurations. Cross-reference access control modification timestamps with legitimate administrative activity. If you observe configuration changes without corresponding admin actions or from unusual source IPs, investigate immediately.
Is this vulnerability actively being exploited?
No. The vulnerability is not currently listed on CISA's Known Exploited Vulnerabilities catalog. However, absence from the KEV list does not guarantee no exploitation—it means no in-the-wild exploitation has been formally documented by federal authorities. Monitor threat intelligence feeds for updates.
Which Sendcloud versions are safe?
Versions after 1.0.29 should include the fix, but verify this in the official Sendcloud security advisory. Request confirmation from Sendcloud support if you are uncertain about a specific version number.
This analysis is based on publicly available information as of the publication date. CVSS scores, patch versions, and vendor advisory details are subject to change. Always consult the official Sendcloud security advisory and your vulnerability management platform for the most current remediation guidance. This explainer does not constitute professional security advice for your specific environment—conduct a risk assessment tailored to your infrastructure, data sensitivity, and business criticality before deciding on patch timelines. Source: NVD (public-domain), retrieved 2026-08-11. Analysis generated by SEC.co (claude-haiku-4-5).
Weaknesses (CWE)
Related vulnerabilities
- CVE-2022-42479MEDIUMMissing Authorization in TemplateHouse Soledad – MEDIUM Severity Access Control Bypass
- CVE-2022-45813MEDIUMBeRocket Advanced AJAX Product Filters Missing Authorization Flaw
- CVE-2023-25969MEDIUMMissing Authorization in ThemeHunk Contact Form Plugin
- CVE-2023-32959MEDIUMMetroStore Missing Authorization Vulnerability – Patch Guide
- CVE-2024-24709MEDIUMShareaholic Missing Authorization Vulnerability – Update Required
- CVE-2024-31435MEDIUMMissing Authorization in Inisev Social Media & Share Icons Plugin—Patch Guidance
- CVE-2024-33685MEDIUMMissing Authorization in Jegstudio Startupzy 1.1.1 – MEDIUM Severity Vulnerability
- CVE-2024-33909MEDIUMMissing Authorization in Avirtum iPages Flipbook – CVSS 5.3 Patch Guide