Weak Password Recovery Mechanism for Forgotten Password in Shopware - #VU145369
Published: August 25, 2026
Vulnerability details
The vulnerability allows a remote attacker to take over an administrator account.
The vulnerability exists due to weak password recovery mechanism in the administration password-recovery flow when generating password-reset links from user-controlled host headers. A remote attacker can cause a reset link for a known administrator account to point to an attacker-controlled domain to take over an administrator account.
User interaction is required because the administrator must open the manipulated link.