CVE-2026-48010

Summary

Shopware is an open commerce platform. Prior to 6.6.10.18 and 6.7.10.1, UserController::upsertUser() in src/Core/Framework/Api/Controller/UserController.php writes raw user data in SYSTEM_SCOPE without filtering the admin field, so a non-admin API user with user:create or user:update ACL permission can set admin: true on new or existing users; IntegrationController::upsertIntegration() contains an isAdmin() check for the same field, but UserController was missing this check. This issue is fixed in versions 6.6.10.18 and 6.7.10.1.

Affected Software

VendorProductVersion RangeStatus
shopwareshopware< 6.6.10.18affected
shopwareshopware>= 6.7.0.0, < 6.7.10.1affected
shopwareplatform< 6.6.10.18affected
shopwareplatform>= 6.7.0.0, < 6.7.10.1affected

Weaknesses

  • CWE-269: CWE-269: Improper Privilege Management

ADP Enrichment

CISA ADP Vulnrichment

  • SSVC:
  • Exploitation: none
    • Automatable: no
    • Technical Impact: total

References