Incorrect authorization in Shopware - #VU145370

 

Incorrect authorization in Shopware - #VU145370

Published: August 25, 2026


Vulnerability identifier: #VU145370
CSH Severity: Medium
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: N/A
CWE-ID: CWE-863
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to disclose unapproved product review information.

The vulnerability exists due to incorrect authorization in nested store-api associations when handling store api requests for product review data. A remote attacker can access review content, rating, and display name fields to disclose unapproved product review information.

The issue exposes reviews that are awaiting moderation and have not been approved for publication.


Affected software

Shopware

Remediation

Install security update from vendor's website.

Shopware - addressed in versions 6.6.10.23, 6.7.13.1

External References

Related Security Bulletins