Executive brief
Shopware is an open-source e-commerce platform used by businesses to manage online stores. A security flaw in the order management system allows staff members with restricted permissions to bypass security checks and change the status of orders, payments, or deliveries. This could lead to unauthorized order cancellations, incorrect shipping updates, or disruption of automated business workflows, potentially causing operational chaos and financial inconsistencies.
Technical details
A vertical authorization bypass exists in Shopware's Admin API within the OrderActionController. The endpoints for order state transitions (e.g., /api/_action/order/{orderId}/state/{transition}) fail to declare the PlatformRequest::ATTRIBUTE_ACL attribute or perform explicit privilege checks. Because the AclAnnotationValidator exits early when ACL metadata is missing, the backend processes these requests even if the user lacks 'order:update' or related permissions. Furthermore, because the StateMachineRegistry executes transitions within SYSTEM_SCOPE, the underlying database writes bypass standard entity-level security once the controller layer is breached. Attackers with low-privileged API access can manipulate order lifecycles, potentially triggering unintended payment or fulfillment workflows. The issue is resolved in versions 6.6.10.18 and 6.7.10.1.
Affected products
- Shopware shopware/core < 6.6.10.18, >= 6.7.0.0, < 6.7.10.1
- Shopware shopware/platform < 6.6.10.18, >= 6.7.0.0, < 6.7.10.1
Timeline
- 2026-05-19: patched: Security releases 6.6.10.18 and 6.7.10.1 published.
- 2026-05-19: advisory: GitHub Security Advisory GHSA-f8q6-3g5w-jjr6 published.
- 2026-07-17: disclosed: CVE-2026-48014 published to NVD.
References
- https://github.com/shopware/shopware/commit/86dff24ba500e16325742e59d20357f57a79c2af
- https://github.com/shopware/shopware/commit/9f15faee704b61e8a96657024fa96c70b47ad082
- https://github.com/shopware/shopware/releases/tag/v6.6.10.18
- https://github.com/shopware/shopware/releases/tag/v6.7.10.1
- https://github.com/shopware/shopware/security/advisories/GHSA-f8q6-3g5w-jjr6