Low severity3.7NVD Advisory· Published Jun 10, 2026· Updated Jun 11, 2026
CVE-2026-48011
CVE-2026-48011
Description
Shopware is an open commerce platform. Prior to versions 6.6.10.18 and 6.7.10.1, an attacker is able to enumerate the usernames of administrator users by performing a timing attack. Versions 6.6.10.18 and 6.7.10.1 fix the issue.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
shopware/platformPackagist | >= 6.7.0.0, < 6.7.10.1 | 6.7.10.1 |
shopware/platformPackagist | < 6.6.10.18 | 6.6.10.18 |
shopware/corePackagist | >= 6.7.0.0, < 6.7.10.1 | 6.7.10.1 |
shopware/corePackagist | < 6.6.10.18 | 6.6.10.18 |
Affected products
3- ghsa-coords2 versions
>= 6.7.0.0, < 6.7.10.1+ 1 more
- (no CPE)range: >= 6.7.0.0, < 6.7.10.1
- (no CPE)range: >= 6.7.0.0, < 6.7.10.1
Patches
Vulnerability mechanics
References
5News mentions
1- Shopware: Nine Vulnerabilities Disclosed, Including Privilege Escalation and XSSVypr Intelligence · Jun 4, 2026