Record summary

CVE-2026-31887 has a selected CVSS score of 8.9 (high).

Description

Shopware is an open commerce platform. Prior to 6.7.8.1 and 6.6.10.15, an insufficient check on the filter types for unauthenticated customers allows access to orders of other customers. This is part of the deepLinkCode support on the store-api.order endpoint. This vulnerability is fixed in 6.7.8.1 and 6.6.10.15.

Description source: CVE List

Exploitation context

CISA SSVC decision

ExploitationNone
AutomatableNo
Technical impactPartial

CISA Coordinator · SSVC 2.0.3 · Evaluated Mar 12, 2026 · Source: CVE List

Affected products and versions

4
ProductSourceVersion rangeStatus
CVE List>= 6.7.0.0, < 6.7.8.1affected
< 6.6.10.15affected
CVE List>= 6.7.0.0, < 6.7.8.1affected
< 6.6.10.15affected
GitHub Advisory6.7.0.0 to < 6.7.8.1 · Fixed in 6.7.8.1affected
Before 6.6.10.15 · Fixed in 6.6.10.15affected
GitHub Advisory6.7.0.0 to < 6.7.8.1 · Fixed in 6.7.8.1affected
Before 6.6.10.15 · Fixed in 6.6.10.15affected

References

3