cpCommerce version 1.2.6 suffers from input variable overwrite and authentication bypass vulnerabilities.