← Volver al buscador de CVEs

CVE-2026-48009

Shopware

Descripción

Shopware is an open commerce platform. Prior to 6.6.10.18 and 6.7.10.1, a low-privilege admin user with user_recovery:read ACL can take over any admin account by triggering POST /api/_action/user/user-recovery, reading the password recovery hash through POST /api/search/user-recovery, and using PATCH /api/_action/user/user-recovery/password; the root cause is that src/Core/System/User/Recovery/UserRecoveryDefinition.php exposes the hash field through the Admin API without ApiAware(false) or ReadProtection. This issue is fixed in versions 6.6.10.18 and 6.7.10.1.

CVSS 6.8EPSS 0.272%Riesgo 0.7
Ver fuente
Publicación
2026-07-17 18:17:15
Versiones afectadas
<6.6.10.18, <6.7.10.1
Tipo
Aplicación web
Vector
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:N