github.com
https://github.com/shopware/shopware CVE-2026-31887
HIGH
Shopware unauthenticated data extraction possible through store-api.order endpoint
Record summary
CVE-2026-31887 has a selected CVSS score of 8.9 (high).
Description
Shopware is an open commerce platform. Prior to 6.7.8.1 and 6.6.10.15, an insufficient check on the filter types for unauthenticated customers allows access to orders of other customers. This is part of the deepLinkCode support on the store-api.order endpoint. This vulnerability is fixed in 6.7.8.1 and 6.6.10.15.
Description source: CVE List
Exploitation context
CISA SSVC decision
ExploitationNone
AutomatableNo
Technical impactPartial
CISA Coordinator · SSVC 2.0.3 · Evaluated Mar 12, 2026 · Source: CVE List
Affected products and versions
4| Product | Source | Version range | Status |
|---|---|---|---|
| CVE List | >= 6.7.0.0, < 6.7.8.1 | affected | |
| < 6.6.10.15 | affected | ||
platformBrowse shopware / platform | CVE List | >= 6.7.0.0, < 6.7.8.1 | affected |
| < 6.6.10.15 | affected | ||
shopware/coreBrowse Packagist / shopware/core | GitHub Advisory | 6.7.0.0 to < 6.7.8.1 · Fixed in 6.7.8.1 | affected |
| Before 6.6.10.15 · Fixed in 6.6.10.15 | affected | ||
shopware/platformBrowse Packagist / shopware/platform | GitHub Advisory | 6.7.0.0 to < 6.7.8.1 · Fixed in 6.7.8.1 | affected |
| Before 6.6.10.15 · Fixed in 6.6.10.15 | affected |
References
3github.comConfirmation
https://github.com/shopware/shopware/security/advisories/GHSA-7vvp-j573-5584 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2026-31887