VYPR
Medium severity6.5GHSA Advisory· Published Jul 17, 2026· Updated Jul 17, 2026

CVE-2026-48008

CVE-2026-48008

Description

Shopware is an open commerce platform. Prior to 6.6.10.18 and 6.7.10.1, a non-admin API user with integration:create ACL privilege can escalate to full administrator by creating an integration with admin: true through the Sync API POST /api/_action/sync; the regular integration endpoint POST /api/integration blocks this, but SyncController::sync() routes writes through SyncService to EntityWriter::upsert(), and src/Core/Framework/Integration/IntegrationDefinition.php lacks WriteProtection on the admin field. This issue is fixed in versions 6.6.10.18 and 6.7.10.1.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
shopware/platformPackagist
>= 6.7.0.0, < 6.7.10.16.7.10.1
shopware/platformPackagist
< 6.6.10.186.6.10.18
shopware/corePackagist
>= 6.7.0.0, < 6.7.10.16.7.10.1
shopware/corePackagist
< 6.6.10.186.6.10.18

Affected products

1

Patches

Vulnerability mechanics

References

6

News mentions

1