Improper Enforcement of Behavioral Workflow in Shopware - #VU150744

 

Improper Enforcement of Behavioral Workflow in Shopware - #VU150744

Published: September 17, 2026


Vulnerability identifier: #VU150744
CSH Severity: Medium
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: N/A
CWE-ID: CWE-841
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to activate unauthorized newsletter subscriptions.

The vulnerability exists due to improper enforcement of the double-opt-in confirmation flow in the Shopware newsletter activation feature when processing Store API newsletter activation requests. A remote attacker can submit a newsletter activation request without proving control of the email address to activate unauthorized newsletter subscriptions.

Email addresses belonging to existing customers can be subscribed.


Affected software

Shopware

Remediation

Install security update from vendor's website.

Shopware - addressed in versions 6.6.10.25, 6.7.14.1

External References

Related Security Bulletins