Improper access control in Shopware - #VU150741
Published: September 17, 2026
Vulnerability details
The vulnerability allows a remote user to escalate privileges.
The vulnerability exists due to improper access control in the profile update functionality when modifying nested properties of their own account. A remote user can modify protected account properties to escalate privileges.
Exploitation requires access to the user's own profile through the user_change_me permission.