CVE-2026-48011lowCWE-208

CVE-2026-48011: low-severity vulnerability in shopware

Shopware: Timing-attack on admin panel allowing enumeration of administrator usernames

Published · Updated

8Vexday Risk Score

No sign of exploitation. No public exploitation artifact known so far.

ssvc Trackcvss 3.7epss 0.4%
exploitation probability
0.4%top 73% of all CVEs
observed exploitation
nono source reports it
Shopware is an open commerce platform. Prior to versions 6.6.10.18 and 6.7.10.1, an attacker is able to enumerate the usernames of administrator users by performing a timing attack. Versions 6.6.10.18 and 6.7.10.1 fix the issue.
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N
Affected products
shopware · shopware