PrestaShop upsshipping <=2.4.0 Remote Info Disclosure via logs and UPSBaseApi.php
CVE-2026-39079 Published on May 18, 2026
An issue in prestashop upsshipping all versions through at least 2.4.0 allows a remote attacker to obtain sensitive information via the /modules/upsshipping/logs/, and /modules/upsshipping/lib/UPSBaseApi.php components
Vulnerability Analysis
CVE-2026-39079 can be exploited with network access, and does not require authorization privileges or user interaction. This vulnerability is considered to have a low attack complexity. An automatable proof of concept (POC) exploit exists. The potential impact of an exploit of this vulnerability is considered to have a high impact on confidentiality, with no impact on integrity and availability.
Weakness Type
What is an Information Disclosure Vulnerability?
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
CVE-2026-39079 has been classified to as an Information Disclosure vulnerability or weakness.
Products Associated with CVE-2026-39079
Want to know whenever a new CVE is published for PrestaShop? stack.watch will email you.