6.5
CVE-2026-48010
- EPSS 0.26%
- Veröffentlicht 17.07.2026 17:55:25
- Zuletzt bearbeitet 18.07.2026 00:16:48
- CVE-Watchlists
- Unerledigt
Shopware: Privilege escalation: non-admin user with user:create ACL can create admin accounts
Shopware is an open commerce platform. Prior to 6.6.10.18 and 6.7.10.1, UserController::upsertUser() in src/Core/Framework/Api/Controller/UserController.php writes raw user data in SYSTEM_SCOPE without filtering the admin field, so a non-admin API user with user:create or user:update ACL permission can set admin: true on new or existing users; IntegrationController::upsertIntegration() contains an isAdmin() check for the same field, but UserController was missing this check. This issue is fixed in versions 6.6.10.18 and 6.7.10.1.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
Herstellershopware
≫
Produkt
shopware
Version
< 6.6.10.18
Status
affected
Version
>= 6.7.0.0, < 6.7.10.1
Status
affected
Herstellershopware
≫
Produkt
platform
Version
< 6.6.10.18
Status
affected
Version
>= 6.7.0.0, < 6.7.10.1
Status
affected
VulnDex Vulnerability Enrichment
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.26% | 0.18 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| security-advisories@github.com | 6.5 | 1.2 | 5.2 |
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:N
|
CWE-269 Improper Privilege Management
The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.
https://github.com/shopware/shopware/releases/tag/v6.6.10.18
https://github.com/shopware/shopware/releases/tag/v6.7.10.1
https://github.com/shopware/shopware/security/advisories/GHSA-v39m-97p8-gqg7
https://github.com/shopware/shopware/commit/7f1cef324ca4edfa6369264cc1c41287d032624d
https://github.com/shopware/shopware/commit/d8d9a34a9255abf69c2798015a17cd6a80b08c25