CVE-2026-48010

MEDIUM

Shopware: Privilege escalation: non-admin user with user:create ACL can create admin accounts

Title source: cna
STIX 2.1

Description

Shopware is an open commerce platform. Prior to 6.6.10.18 and 6.7.10.1, UserController::upsertUser() in src/Core/Framework/Api/Controller/UserController.php writes raw user data in SYSTEM_SCOPE without filtering the admin field, so a non-admin API user with user:create or user:update ACL permission can set admin: true on new or existing users; IntegrationController::upsertIntegration() contains an isAdmin() check for the same field, but UserController was missing this check. This issue is fixed in versions 6.6.10.18 and 6.7.10.1.

Scores

CVSS v3 6.5
EPSS 0.0026
EPSS Percentile 18.2%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-269
Status published
Products (4)
shopware/platform < 6.6.10.18
shopware/platform >= 6.7.0.0, < 6.7.10.1
shopware/shopware < 6.6.10.18
shopware/shopware >= 6.7.0.0, < 6.7.10.1
Published Jul 17, 2026
Tracked Since Jul 18, 2026