CVE-2026-31889: high-severity vulnerability in shopware platform
Shopware has a potential take over of app credentials
Published · Updated
21Vexday Risk Score
No sign of exploitation. No public exploitation artifact known so far.
ssvc Trackcvss 8.9epss 0.4%
exploitation probability
0.4%top 67% of all CVEs
observed exploitation
nono source reports it
Shopware is an open commerce platform. Prior to 6.6.10.15 and 6.7.8.1, a vulnerability in the Shopware app registration flow that could, under specific conditions, allow attackers to take over the communication channel between a shop and an app. The legacy app registration flow used HMAC‑based authentication without sufficiently binding a shop installation to its original domain. During re‑registration, the shop-url could be updated without proving control over the previously registered shop or domain. This made targeted hijacking of app communication feasible if an attacker possessed the relevant app‑side secret. By abusing app re‑registration, an attacker could redirect app traffic to an attacker‑controlled domain and potentially obtain API credentials intended for the legitimate shop. This vulnerability is fixed in 6.6.10.15 and 6.7.8.1.
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:L
Related CVEs — shopware platform
In the same product, most dangerous first.
CVE-2021-37708HIGHCommand injection in mail agent settingsEPSS 2.4%CVE-2021-32717HIGHPrivate files publicly accessible with Cloud Storage providersEPSS 1.5%CVE-2021-32711CRITICALLeak of information via Store-APIEPSS 1.4%CVE-2023-22731CRITICALImproper Control of Generation of Code in Twig rendered views in shopwareEPSS 1.3%CVE-2021-32716MEDIUMInternal hidden fields are visible on to many associations in admin apiEPSS 1.1%CVE-2022-24747MEDIUMHTTP caching is marking private HTTP headers as publicEPSS 1.1%