Observable Response Discrepancy in Shopware - CVE-2026-31888
Published: May 20, 2026
Shopware
Detailed vulnerability description
The vulnerability allows a remote attacker to enumerate valid customer accounts.
The vulnerability exists due to observable response discrepancy in the Store API login endpoint when handling login requests. A remote attacker can submit crafted login attempts with probed email addresses to enumerate valid customer accounts.
The unknown-email response reflects the submitted email address in the error detail and metadata.