CVE-2026-48011

Shopware is an open commerce platform. Prior to versions 6.6.10.18 and 6.7.10.1, an attacker is able to enumerate the usernames of administrator users by performing a timing attack. Versions 6.6.10.18 and 6.7.10.1 fix the issue.
Configurations

No configuration.

History

No history.

Information

Published : 2026-06-10 22:17

Updated : 2026-07-23 09:10


NVD link : CVE-2026-48011

Mitre link : CVE-2026-48011

CVE.ORG link : CVE-2026-48011


JSON object : View

Products Affected

No product.

CWE
CWE-208

Observable Timing Discrepancy