SB20260825139 - Multiple vulnerabilities in Shopware



SB20260825139 - Multiple vulnerabilities in Shopware

Published: August 25, 2026

Security Bulletin ID SB20260825139
CSH Severity
High
Patch available
YES
Number of vulnerabilities 10
Exploitation vector Remote access
Highest impact Code execution

Breakdown by Severity

High 30% Medium 10% Low 60%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 10 vulnerabilities.


1) SQL injection (CVE-ID: N/A)

CWE-ID: CWE-89 - Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

CVSSv4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote user to execute arbitrary SQL commands.

The vulnerability exists due to SQL injection in custom-entity definitions in the app manifest when processing custom entity field names supplied by apps. A remote privileged user can supply a crafted custom-entity definition to execute arbitrary SQL commands.

Exploitation may allow reading, modifying, or deleting shop data, altering the database schema, or disrupting the shop.


2) Improperly Controlled Modification of Dynamically-Determined Object Attributes (CVE-ID: N/A)

CWE-ID: CWE-915 - Improperly Controlled Modification of Dynamically-Determined Object Attributes

CVSSv4: 8.5 [CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote user to escalate privileges.

The vulnerability exists due to improperly controlled modification of dynamically-determined object attributes in the user-update operation when handling user update requests. A remote privileged user can assign additional ACL roles to gain privileges beyond those originally granted.

Exploitation requires permission to update users in the Administration interface.


3) Path traversal (CVE-ID: N/A)

CWE-ID: CWE-22 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

CVSSv4: 7.5 [CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote user to execute arbitrary code.

The vulnerability exists due to path traversal in the media update functionality when updating a media file extension. A remote privileged user can modify the media file extension to write files outside the intended media directory to execute arbitrary code.

Exploitation requires the media:update privilege and may lead to full compromise of the shop in affected configurations.


4) Improper Neutralization of Special Elements Used in a Template Engine (CVE-ID: N/A)

CWE-ID: CWE-1336 - Improper Neutralization of Special Elements Used in a Template Engine

CVSSv4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to execute arbitrary PHP functions and operating-system commands.

The vulnerability exists due to improper neutralization of special elements used in a template engine in the App Script sandbox when processing app scripts. A remote attacker can install and activate a malicious or compromised App to execute arbitrary PHP functions and operating-system commands.

User interaction is required to trigger exploitation.


5) SQL injection (CVE-ID: N/A)

CWE-ID: CWE-89 - Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

CVSSv4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to disclose sensitive information.

The vulnerability exists due to SQL injection in Store API aggregation handling when processing aggregation names. A remote attacker can send crafted Store API requests to disclose sensitive information.

Exploitation requires a valid Sales Channel access key, which may be exposed by design in headless Store API integrations.


6) Weak Password Recovery Mechanism for Forgotten Password (CVE-ID: N/A)

CWE-ID: CWE-640 - Weak password recovery mechanism

CVSSv4: 8.5 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to take over an administrator account.

The vulnerability exists due to weak password recovery mechanism in the administration password-recovery flow when generating password-reset links from user-controlled host headers. A remote attacker can cause a reset link for a known administrator account to point to an attacker-controlled domain to take over an administrator account.

User interaction is required because the administrator must open the manipulated link.


7) Incorrect authorization (CVE-ID: N/A)

CWE-ID: CWE-863 - Incorrect Authorization

CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to disclose unapproved product review information.

The vulnerability exists due to incorrect authorization in nested store-api associations when handling store api requests for product review data. A remote attacker can access review content, rating, and display name fields to disclose unapproved product review information.

The issue exposes reviews that are awaiting moderation and have not been approved for publication.


8) Server-Side Request Forgery (SSRF) (CVE-ID: N/A)

CWE-ID: CWE-918 - Server-Side Request Forgery (SSRF)

CVSSv4: 6 [CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:N/VA:N/SC:L/SI:N/SA:N]


The vulnerability allows a remote user to disclose sensitive information from internal network services.

The vulnerability exists due to server-side request forgery (SSRF) in the media URL import feature when importing media from an external URL. A remote user can supply a URL that bypasses IP validation through DNS rebinding to disclose sensitive information from internal network services.

The issue may expose cloud-instance metadata depending on the hosting environment.


9) Improper Restriction of Excessive Authentication Attempts (CVE-ID: N/A)

CWE-ID: CWE-307 - Improper Restriction of Excessive Authentication Attempts

CVSSv4: 6.3 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to disclose sensitive information.

The vulnerability exists due to improper restriction of excessive authentication attempts in DocumentRoute guest authentication when handling guest document-download requests. A remote attacker can repeatedly guess the postal code for a valid document download link to disclose sensitive information.

Exploitation requires a valid document download link and knowledge of the recipient\'s email address.


10) Server-Side Request Forgery (SSRF) (CVE-ID: N/A)

CWE-ID: CWE-918 - Server-Side Request Forgery (SSRF)

CVSSv4: 1.8 [CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote user to disclose sensitive information and modify data via server-side request forgery.

The vulnerability exists due to server-side request forgery in the Shopware App System request handling for app-provided webhook, payment, tax, checkout, and context gateway URLs when processing app-provided URLs. A remote privileged user can use DNS rebinding in a crafted app-provided URL to disclose sensitive information and modify data via server-side request forgery.

User interaction is required to install or use a malicious or compromised app.


Remediation

Install update from vendor's website.