Weak Password Recovery Mechanism for Forgotten Password in Shopware - #VU145369

 

Weak Password Recovery Mechanism for Forgotten Password in Shopware - #VU145369

Published: August 25, 2026


Vulnerability identifier: #VU145369
CSH Severity: High
CVSS v4: 8.5 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N]
CVE-ID: N/A
CWE-ID: CWE-640
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to take over an administrator account.

The vulnerability exists due to weak password recovery mechanism in the administration password-recovery flow when generating password-reset links from user-controlled host headers. A remote attacker can cause a reset link for a known administrator account to point to an attacker-controlled domain to take over an administrator account.

User interaction is required because the administrator must open the manipulated link.


Affected software

Shopware

Remediation

Install security update from vendor's website.

Shopware - addressed in versions 6.6.10.23, 6.7.13.1

External References

Related Security Bulletins