CVE-2026-48010

Shopware is an open commerce platform. Prior to 6.6.10.18 and 6.7.10.1, UserController::upsertUser() in src/Core/Framework/Api/Controller/UserController.php writes raw user data in SYSTEM_SCOPE without filtering the admin field, so a non-admin API user with user:create or user:update ACL permission can set admin: true on new or existing users; IntegrationController::upsertIntegration() contains an isAdmin() check for the same field, but UserController was missing this check. This issue is fixed in versions 6.6.10.18 and 6.7.10.1.
Configurations

No configuration.

History

No history.

Information

Published : 2026-07-17 18:17

Updated : 2026-07-18 00:16


NVD link : CVE-2026-48010

Mitre link : CVE-2026-48010

CVE.ORG link : CVE-2026-48010


JSON object : View

Products Affected

No product.

CWE
CWE-269

Improper Privilege Management