CVE-2026-92809 Details
Description
PrestaShop psgdpr versions through 1.4.3 fail to validate that GDPR consent log entries are attributed to the authenticated customer. Authenticated attackers can submit arbitrary customer identifiers to create forged consent records for other customers, corrupting audit logs.
A vulnerability exists in the PrestaShop psgdpr module, specifically in versions through 1.4.3, allowing authenticated attackers to manipulate GDPR consent logs. The issue arises because the module fails to ensure that consent records are accurately attributed to the logged-in customer. Instead, attackers can inject arbitrary customer IDs to create fake consent entries for other users, thereby disrupting the integrity of the audit logs. This flaw is located in the 'FrontAjaxGdpr' controller, which handles consent log actions via user-supplied data.
Users are advised to update to PrestaShop psgdpr version 2.0.0 or later, where this vulnerability has been addressed.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Sep 16, 2026CISA-ADP
Assessed Sep 17, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-639 | Authorization Bypass Through User-Controlled Key | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| PrestaShop psgdpr | <= 1.4.3 (semver) |
CPE
Remediation
| |
Change History
2 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Sep 17, 2026 | CVE Modified | CISA-ADP |
| Sep 16, 2026 | New CVE Received | [email protected] |
Volerion