CVE-2026-31889: falha de alta gravidade em shopware platform
Shopware has a potential take over of app credentials
Publicada em · Atualizada em
21Vexday Risk Score
Sem sinal de exploração. Nenhum artefato público de exploração conhecido até agora.
ssvc Trackcvss 8.9epss 0.4%
probabilidade de exploração
0.4%top 67% das CVEs
exploração observada
nãonenhuma fonte reporta
Shopware is an open commerce platform. Prior to 6.6.10.15 and 6.7.8.1, a vulnerability in the Shopware app registration flow that could, under specific conditions, allow attackers to take over the communication channel between a shop and an app. The legacy app registration flow used HMAC‑based authentication without sufficiently binding a shop installation to its original domain. During re‑registration, the shop-url could be updated without proving control over the previously registered shop or domain. This made targeted hijacking of app communication feasible if an attacker possessed the relevant app‑side secret. By abusing app re‑registration, an attacker could redirect app traffic to an attacker‑controlled domain and potentially obtain API credentials intended for the legitimate shop. This vulnerability is fixed in 6.6.10.15 and 6.7.8.1.
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:L
CVEs relacionadas — shopware platform
No mesmo produto, das mais perigosas para as menos.
CVE-2021-37708HIGHCommand injection in mail agent settingsEPSS 2.4%CVE-2021-32717HIGHPrivate files publicly accessible with Cloud Storage providersEPSS 1.5%CVE-2021-32711CRITICALLeak of information via Store-APIEPSS 1.4%CVE-2023-22731CRITICALImproper Control of Generation of Code in Twig rendered views in shopwareEPSS 1.3%CVE-2021-32716MEDIUMInternal hidden fields are visible on to many associations in admin apiEPSS 1.1%CVE-2022-24747MEDIUMHTTP caching is marking private HTTP headers as publicEPSS 1.1%