6.5
CVE-2026-48008
- EPSS 0.26%
- Veröffentlicht 17.07.2026 17:47:27
- Zuletzt bearbeitet 17.07.2026 20:17:19
- CVE-Watchlists
- Unerledigt
Shopware: Privilege Escalation via Sync API Integration Admin Flag Bypass
Shopware is an open commerce platform. Prior to 6.6.10.18 and 6.7.10.1, a non-admin API user with integration:create ACL privilege can escalate to full administrator by creating an integration with admin: true through the Sync API POST /api/_action/sync; the regular integration endpoint POST /api/integration blocks this, but SyncController::sync() routes writes through SyncService to EntityWriter::upsert(), and src/Core/Framework/Integration/IntegrationDefinition.php lacks WriteProtection on the admin field. This issue is fixed in versions 6.6.10.18 and 6.7.10.1.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
Herstellershopware
≫
Produkt
shopware
Version
< 6.6.10.18
Status
affected
Version
>= 6.7.0.0, < 6.7.10.1
Status
affected
Herstellershopware
≫
Produkt
platform
Version
< 6.6.10.18
Status
affected
Version
>= 6.7.0.0, < 6.7.10.1
Status
affected
VulnDex Vulnerability Enrichment
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.26% | 0.18 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| security-advisories@github.com | 6.5 | 1.2 | 5.2 |
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:N
|
CWE-862 Missing Authorization
The product does not perform an authorization check when an actor attempts to access a resource or perform an action.
https://github.com/shopware/shopware/releases/tag/v6.6.10.18
https://github.com/shopware/shopware/releases/tag/v6.7.10.1
https://github.com/shopware/shopware/security/advisories/GHSA-gv8p-48fr-4fxg
https://github.com/shopware/shopware/commit/1e047f6d7fd9129271e28c1c9f1c272983c6f48f
https://github.com/shopware/shopware/commit/db5adff33ec30b648979cd1938c87f164f7b3073