Improper access control in Shopware - #VU131904
Published: May 20, 2026
Shopware
Detailed vulnerability description
The vulnerability allows a remote user to reset a customer's password.
The vulnerability exists due to improper access control in the password recovery mechanism when processing a password reset link after an email address change. A remote privileged user can use a previously issued password recovery link tied to the old email address to reset a customer's password.
Exploitation requires access to the old email inbox after a password reset was requested and before the email address was changed.