Executive brief
Shopware is an open-source e-commerce platform used by businesses to manage online stores. A security flaw allows a user with limited API access to elevate their permissions to full administrator status. By exploiting this, an attacker could gain complete control over the store, including the ability to access customer personal data, modify orders, and change system configurations.
Technical details
A privilege escalation vulnerability exists in Shopware's Sync API due to missing authorization checks in the Data Abstraction Layer (DAL). While the standard integration endpoint (POST /api/integration) correctly restricts the creation of admin-level integrations to existing administrators, the Sync API (POST /api/_action/sync) bypasses these controller-level checks. The root cause is that 'IntegrationDefinition.php' lacks 'WriteProtection' on the 'admin' field, allowing the 'EntityWriter' to upsert administrative privileges for any user with 'integration:create' permissions. An attacker with high-privileged (but non-admin) API access can use this to gain full administrative control over the platform. This issue is fixed in versions 6.6.10.18 and 6.7.10.1.
Affected products
- Shopware shopware/core < 6.6.10.18, >= 6.7.0.0 < 6.7.10.1
- Shopware shopware/platform < 6.6.10.18, >= 6.7.0.0 < 6.7.10.1
Timeline
- 2026-05-19: patched: Security releases 6.6.10.18 and 6.7.10.1 published.
- 2026-05-19: advisory: GitHub Security Advisory GHSA-gv8p-48fr-4fxg published.
- 2026-07-17: disclosed: CVE-2026-48008 published to NVD.
References
- https://github.com/shopware/shopware/commit/1e047f6d7fd9129271e28c1c9f1c272983c6f48f
- https://github.com/shopware/shopware/commit/db5adff33ec30b648979cd1938c87f164f7b3073
- https://github.com/shopware/shopware/releases/tag/v6.6.10.18
- https://github.com/shopware/shopware/releases/tag/v6.7.10.1
- https://github.com/shopware/shopware/security/advisories/GHSA-gv8p-48fr-4fxg