Improper access control in Shopware - CVE-2026-31887
Published: May 20, 2026
Shopware
Detailed vulnerability description
The vulnerability allows a remote attacker to disclose sensitive information.
The vulnerability exists due to improper access control in the store-api.order endpoint when processing deepLinkCode-supported order filter requests. A remote attacker can send a specially crafted request to disclose sensitive information.
Exploitation can expose foreign customer order data and enable mass enumeration of recent orders.