CVE-2026-31888Observable Response Discrepancy in Core

Severity
5.3MEDIUMNVD
EPSS
0.1%
top 83.72%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMar 11

Description

Shopware is an open commerce platform. Prior to 6.7.8.1 and 6.6.10.15, the Store API login endpoint (POST /store-api/account/login) returns different error codes depending on whether the submitted email address belongs to a registered customer (CHECKOUT__CUSTOMER_AUTH_BAD_CREDENTIALS) or is unknown (CHECKOUT__CUSTOMER_NOT_FOUND). The "not found" response also echoes the probed email address. This allows an unauthenticated attacker to enumerate valid customer accounts. The storefront login contro

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:NExploitability: 3.9 | Impact: 1.4

Affected Packages5 packages

CVEListV5shopware/platform< 6.6.10.14+1
Packagistshopware/platform6.7.0.06.7.8.1+1
CVEListV5shopware/core< 6.6.10.15+1
Packagistshopware/core6.7.0.06.7.8.1+1
NVDshopware/shopware6.7.0.06.7.8.1+1

🔴Vulnerability Details

2
OSV
Shopware has user enumeration via distinct error codes on Store API login endpoint2026-03-11
GHSA
Shopware has user enumeration via distinct error codes on Store API login endpoint2026-03-11

🕵️Threat Intelligence

1
Wiz
CVE-2026-31888 Impact, Exploitability, and Mitigation Steps | Wiz