Feed/CVE-2026-31887
CVE-2026-31887HIGHCVSS 0.0

CVE-2026-31887

Published Mar 11, 2026·Updated Sep 10, 2026

NVD Description

Shopware is an open commerce platform. Prior to 6.7.8.1 and 6.6.10.15, an insufficient check on the filter types for unauthenticated customers allows access to orders of other customers. This is part of the deepLinkCode support on the store-api.order endpoint. This vulnerability is fixed in 6.7.8.1 and 6.6.10.15.

Affected Packages (2)

shopware/coreCOMPOSER
From 6.7.0.0
Fixed in 6.7.8.1
shopware/platformCOMPOSER
From 6.7.0.0
Fixed in 6.7.8.1

CVSS Vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

References

View on NVD Search GitHub Search Google

Get alerted for CVEs like this

Register your stack and get notified within minutes when a matching CVE drops.

Start monitoring free