Improper Authorization in Shopware - #VU131953
Published: May 20, 2026
Shopware
Detailed vulnerability description
The vulnerability allows a remote user to modify order lifecycle states without intended privileges.
The vulnerability exists due to improper access control in order state transition endpoints when handling direct Admin API transition requests. A remote user can send a specially crafted transition request to modify order lifecycle states without intended privileges.
The issue affects order, order-transaction, and order-delivery transition routes, and direct API calls succeed even when equivalent normal update requests are rejected.