CVE-2026-31889Disclosure(shopware / shopware)

LOWCVSS 8.9 · HIGH

Signal is active with 3 mentions in latest observed window

Immediate actions

  • Patch shopware shopware systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Shopware is an open commerce platform. Prior to 6.6.10.15 and 6.7.8.1, a vulnerability in the Shopware app registration flow that could, under specific conditions, allow attackers to take over the communication channel between a shop and an app. The legacy app registration flow used HMAC‑based authentication without sufficiently binding a shop installation to its original domain. During re‑registration, the shop-url could be updated without proving control over the previously registered shop or domain. This made targeted hijacking of app communication feasible if an attacker possessed the relevant app‑side secret. By abusing app re‑registration, an attacker could redirect app traffic to an attacker‑controlled domain and potentially obtain API credentials intended for the legitimate shop. This vulnerability is fixed in 6.6.10.15 and 6.7.8.1.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-290

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • shopware

Threat summary

  • Patch or workaround signal is available
  • 3 mentions across 1 observed day

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 2 signals
  • Disclosure: 1 classified signal
  • General: 1 classified signal
  • 3 total mentions across 1 day

Affected systems

Vendors
Products
shopware

Deep dive

Activity timeline3 mentions / 1d
01223Mentions · 2026-03-11: 3Patch / Workaround · 2026-03-11: 1Technical Details · 2026-03-11: 203-11
Signal classification3 categories
Disclosure
133.3%
General
133.3%
Patch
133.3%
Referenced assets3 URLs
Full discourse3 posts
  • CVE@CVEnew
    Disclosure

    CVE-2026-31889 Shopware is an open commerce platform. Prior to 6.6.10.15 and 6.7.8.1, a vulnerability in the Shopware app registration flow that could, under specific conditions, al… https://www.cve.org/CVERecord?id=CVE-2026-31889

    Post summary

    The content announces a Shopware vulnerability affecting the app registration flow before specific versions, but offers no details on exploitation, PoCs, patches, or technical specifics.

    00020289
    56.6K followersView on X
  • Infoflowcloud@infoflowcloud
    General

    🚨*CVE* CVE-2026-31889 Shopware is an open commerce platform. Prior to 6.6.10.15 and 6.7.8.1, a vulnerability in the Shopware app registration flow that could, under specific conditions, al… https://www.cve.org/CVERecord?id=CVE-2026-31889 ----- Traducción: CVE-2026-31889 Sho… http://infoflow.cloud`

    Post summary

    A brief notice referencing CVE‑2026‑31889 in Shopware, noting affected versions and the registration‑flow vulnerability but lacking detailed exploitation or mitigation information.

    0000030
    57 followersView on X
  • CVEFind.com@CveFindCom
    Patch

    [CVE-2026-31889: HIGH] Vulnerability in Shopware's app registration flow before versions 6.6.10.15 and 6.7.8.1 could allow attackers to hijack communication channels. Update to prevent cyber threats.#cve,CVE-2026-31889,#cybersecurity https://cvefind.com/CVE-2026-31889

    Post summary

    The tweet announces a high‑severity vulnerability (CVE‑2026‑31889) in Shopware’s app registration flow, advises users to update, and includes version specifics.

    0000027
    600 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appshopwareshopware---

Explore more