Improperly Controlled Modification of Dynamically-Determined Object Attributes in Shopware - #VU145365

 

Improperly Controlled Modification of Dynamically-Determined Object Attributes in Shopware - #VU145365

Published: August 25, 2026


Vulnerability identifier: #VU145365
CSH Severity: Low
CVSS v4: 8.5 [CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N]
CVE-ID: N/A
CWE-ID: CWE-915
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to escalate privileges.

The vulnerability exists due to improperly controlled modification of dynamically-determined object attributes in the user-update operation when handling user update requests. A remote privileged user can assign additional ACL roles to gain privileges beyond those originally granted.

Exploitation requires permission to update users in the Administration interface.


Affected software

Shopware

Remediation

Install security update from vendor's website.

Shopware - addressed in versions 6.6.10.23, 6.7.13.1

External References

Related Security Bulletins