Improperly Controlled Modification of Dynamically-Determined Object Attributes in Shopware - #VU145365
Published: August 25, 2026
Vulnerability details
The vulnerability allows a remote user to escalate privileges.
The vulnerability exists due to improperly controlled modification of dynamically-determined object attributes in the user-update operation when handling user update requests. A remote privileged user can assign additional ACL roles to gain privileges beyond those originally granted.
Exploitation requires permission to update users in the Administration interface.