logo

How a Privilege Escalation Led to Unrestricted Admin Account Creation in Shopify

ID: 092ec682-9240-5dd1-aca6-3a75e43311e3

STIX ID: report--092ec682-9240-5dd1-aca6-3a75e43311e3

Feed Name: HackerOne Blog

Threat Score
55/100

Date Published: 2024-12-12

Date Updated: 2026-06-12

...
...

**Executive Summary:** The report documents a privilege escalation vulnerability in a Shopify app that allowed an authenticated low-privilege user to create and authenticate as an administrative account via the /users/create_admin endpoint; researcher @stapia responsibly disclosed the issue, received a $1,600 bounty, and Shopify patched the flaw on 2021-08-25. It includes step-by-step reproduction, identifies causes (improper token scoping, RBAC and PoLP weaknesses), and recommends mitigations such as scoped single-use tokens, stronger authentication, input validation, and periodic permission reviews.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.