Junglewise Threat Intelligence

CVE-2026-48011: Shopware username enumeration via timing attack in admin panel

CVE-2026-48011 · Severity: low · CVSS 3.7 · Published 2026-06-10

Technologies: Shopware. Vendors: Shopware.

Executive brief

Shopware is an open-source e-commerce platform used by businesses to manage online stores. A security flaw in the administrator login process allows unauthorized individuals to determine which usernames exist on the system by measuring how long the server takes to respond to login attempts. This information can be used to launch more effective targeted cyberattacks, such as password guessing or social engineering, against specific staff members.

Technical details

A timing discrepancy exists in the `getUserEntityByUserCredentials` method within `UserRepository.php`. The application performs an early return if a username is not found in the database, whereas it proceeds to execute the computationally expensive `password_verify` function (using Argon2id) if the username exists. By measuring the response time of requests to the `api/oauth/token` endpoint, a remote attacker can distinguish between valid and invalid administrator usernames. This vulnerability is classified as CWE-208 (Observable Timing Discrepancy). The issue is resolved in versions 6.6.10.18 and 6.7.10.1 by ensuring a dummy hash is verified even when a user is not found.

Affected products

  • Shopware Shopware >= 6.7.0.0, < 6.7.10.1; < 6.6.10.18

Timeline

  • 2026-05-19: patched: Security releases 6.6.10.18 and 6.7.10.1 published
  • 2026-06-10: disclosed: CVE-2026-48011 published

References

Related threats