Executive brief
Shopware is a popular open-source e-commerce platform used to run online stores. A flaw in its order retrieval API allows attackers without authentication to view and download order information of any customer, including names, addresses, email addresses, and payment details. An attacker can enumerate recent orders in bulk and scrape customer personal information, creating significant privacy and compliance risks (GDPR, PCI-DSS) for affected merchants.
Technical details
The vulnerability is an incorrect authorization issue (CWE-863) in the store-api.order endpoint where filter type validation is insufficient for unauthenticated requests. The deepLinkCode support mechanism fails to properly restrict access, allowing attackers to bypass authentication and retrieve arbitrary customer orders. Attack vector is network-based with low complexity; no privileges or user interaction required. An attacker can extract customer names, billing/shipping addresses, email addresses, ordered products, order values, order numbers, dates, payment and shipping methods, and custom fields depending on payload configuration. The code has been present since ~2021, suggesting near-universal impact across versions. Patches available: Shopware 6.7.8.1 and 6.6.10.15+.
Affected products
- Shopware shopware/core >= 6.7.0.0, < 6.7.8.1; < 6.6.10.15
- Shopware shopware/platform >= 6.7.0.0, < 6.7.8.1; < 6.6.10.15
Timeline
- 2026-03-11: disclosed: Advisory published by GitHub
- 2026-03-11: patched: Patches released: shopware/core and shopware/platform versions 6.7.8.1 and 6.6.10.15