Missing Authorization in Shopware - #VU150743
Published: September 17, 2026
Vulnerability details
The vulnerability allows a remote user to disclose sensitive information and enable further compromise.
The vulnerability exists due to missing authorization in webhook event-level authorization checks when creating webhooks for subscribed events. A remote user can create a webhook subscribed to an event to disclose sensitive information and enable further compromise.
Exposed event data may include customer, order, business-process, email-related, and account-recovery information.