Improper Enforcement of Behavioral Workflow in Shopware - #VU150744
Published: September 17, 2026
Vulnerability details
The vulnerability allows a remote attacker to activate unauthorized newsletter subscriptions.
The vulnerability exists due to improper enforcement of the double-opt-in confirmation flow in the Shopware newsletter activation feature when processing Store API newsletter activation requests. A remote attacker can submit a newsletter activation request without proving control of the email address to activate unauthorized newsletter subscriptions.
Email addresses belonging to existing customers can be subscribed.