cbcvebase.
CVE-2026-23498
published 2026-01-14

CVE-2026-23498: Shopware is an open commerce platform. From 6.7.0.0 to before 6.7.6.1, a regression of CVE-2023-2017 leads to an array and array crafted PHP Closure not…

PriorityP342high7.2CVSS 3.1
AVNACLPRHUINSUCHIHAH
EPSS
0.41%
32.9th percentile
Shopware is an open commerce platform. From 6.7.0.0 to before 6.7.6.1, a regression of CVE-2023-2017 leads to an array and array crafted PHP Closure not checked being against allow list for the map(...) override. This vulnerability is fixed in 6.7.6.1.

Affected

3 ranges
VendorProductVersion rangeFixed in
shopwarecore>= 6.7.0.0 < 6.7.6.16.7.6.1
shopwareshopware>= 6.7.0.0 < 6.7.6.16.7.6.1
shopwareshopware>= 6.7.0.0 < 6.7.6.16.7.6.1

CVSS provenance

nvdv3.17.2HIGHCVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
ghsa8.8HIGH
osv8.8HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.