CVE-2026-39079 Details
Description
An issue in prestashop upsshipping all versions through at least 2.4.0 allows a remote attacker to obtain sensitive information via the /modules/upsshipping/logs/, and /modules/upsshipping/lib/UPSBaseApi.php components
A vulnerability allowing sensitive data exposure has been identified in the PrestaShop UPS Shipping Module (upsshipping), all versions through at least 2.4.0. This issue arises from the lack of access control on the module's logs directory, which is publicly accessible via HTTP. As a result, a remote attacker can easily retrieve XML log files containing sensitive information such as UPS API credentials, shipper account numbers, customer personal information, and merchant tax identification numbers.
No official patch is available for this vulnerability, and the vendor is defunct. The recommended course of action is to completely remove the upsshipping module from the PrestaShop installation and migrate to a maintained shipping module. After removal, any remaining XML log files should be purged, UPS API credentials should be rotated, and the activity on the UPS account should be reviewed for unauthorized shipments.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed May 18, 2026CISA-ADP
Assessed May 18, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://labs.esokia.com/cve/cve-2026-39079/ | CISA-ADP | AdvisoryExploitRemedyTechnical Analysis |
| https://labs.esokia.com/cve/cve-2026-39079/ | [email protected] | AdvisoryExploitRemedyTechnical Analysis |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-200 | Exposure of Sensitive Information to an Unauthorized Actor | CISA-ADP |
Affected Products
| Product | Versions |
|---|---|
| PrestaShop | <= 2.4.0 (semver) |
CPE
Remediation
| |
| Agence Web 360 UPS Shipping Module | All versions |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| May 18, 2026 | CVE Modified | CISA-ADP |
| May 18, 2026 | New CVE Received | [email protected] |
Volerion