Executive brief
Shopware is an open-source e-commerce platform used to build and manage online stores. A security flaw in the user management system allows a staff member with limited permissions to grant themselves or others full administrator access. This could lead to an unauthorized takeover of the entire store management panel, potentially exposing customer data and business operations.
Technical details
A privilege escalation vulnerability exists in Shopware's UserController::upsertUser() method. The component processes raw request data within the SYSTEM_SCOPE, which bypasses the AclWriteValidator. Unlike the IntegrationController, the UserController lacks a check to verify if the requesting user has administrative privileges before allowing the 'admin' boolean field to be set. An attacker with existing 'user:create' or 'user:update' ACL permissions can exploit this via the API to promote any account to full administrator status. The issue is resolved in versions 6.6.10.18 and 6.7.10.1 by implementing proper isAdmin() checks.
Affected products
- Shopware shopware/core < 6.6.10.18, >= 6.7.0.0, < 6.7.10.1
- Shopware shopware/platform < 6.6.10.18, >= 6.7.0.0, < 6.7.10.1
Timeline
- 2026-05-19: patched: Security releases 6.6.10.18 and 6.7.10.1 published.
- 2026-07-17: disclosed: CVE-2026-48010 published.
References
- https://github.com/shopware/shopware/commit/7f1cef324ca4edfa6369264cc1c41287d032624d
- https://github.com/shopware/shopware/commit/d8d9a34a9255abf69c2798015a17cd6a80b08c25
- https://github.com/shopware/shopware/releases/tag/v6.6.10.18
- https://github.com/shopware/shopware/releases/tag/v6.7.10.1
- https://github.com/shopware/shopware/security/advisories/GHSA-v39m-97p8-gqg7