VYPR
Medium severity6.5GHSA Advisory· Published Jul 17, 2026· Updated Jul 18, 2026

CVE-2026-48010

CVE-2026-48010

Description

Shopware is an open commerce platform. Prior to 6.6.10.18 and 6.7.10.1, UserController::upsertUser() in src/Core/Framework/Api/Controller/UserController.php writes raw user data in SYSTEM_SCOPE without filtering the admin field, so a non-admin API user with user:create or user:update ACL permission can set admin: true on new or existing users; IntegrationController::upsertIntegration() contains an isAdmin() check for the same field, but UserController was missing this check. This issue is fixed in versions 6.6.10.18 and 6.7.10.1.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
shopware/platformPackagist
>= 6.7.0.0, < 6.7.10.16.7.10.1
shopware/platformPackagist
< 6.6.10.186.6.10.18
shopware/corePackagist
>= 6.7.0.0, < 6.7.10.16.7.10.1
shopware/corePackagist
< 6.6.10.186.6.10.18

Affected products

1

Patches

Vulnerability mechanics

References

6

News mentions

1