CVE-2026-31889
published 2026-03-11CVE-2026-31889: Shopware is an open commerce platform. Prior to 6.6.10.15 and 6.7.8.1, a vulnerability in the Shopware app registration flow that could, under specific…
PriorityP357high8.9CVSS 3.1
AVNACHPRNUINSCCHIHAL
EPSS
0.27%
18.5th percentile
Shopware is an open commerce platform. Prior to 6.6.10.15 and 6.7.8.1, a vulnerability in the Shopware app registration flow that could, under specific conditions, allow attackers to take over the communication channel between a shop and an app. The legacy app registration flow used HMAC‑based authentication without sufficiently binding a shop installation to its original domain. During re‑registration, the shop-url could be updated without proving control over the previously registered shop or domain. This made targeted hijacking of app communication feasible if an attacker possessed the relevant app‑side secret. By abusing app re‑registration, an attacker could redirect app traffic to an attacker‑controlled domain and potentially obtain API credentials intended for the legitimate shop. This vulnerability is fixed in 6.6.10.15 and 6.7.8.1.
Affected
10 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| shopware | core | < 6.6.10.15 | 6.6.10.15 |
| shopware | core | — | — |
| shopware | core | >= 0 < 6.6.10.15 | 6.6.10.15 |
| shopware | core | >= 6.7.0.0 < 6.7.8.1 | 6.7.8.1 |
| shopware | platform | < 6.6.10.15 | 6.6.10.15 |
| shopware | platform | — | — |
| shopware | platform | >= 0 < 6.6.10.15 | 6.6.10.15 |
| shopware | platform | >= 6.7.0.0 < 6.7.8.1 | 6.7.8.1 |
| shopware | shopware | < 6.6.10.15 | 6.6.10.15 |
| shopware | shopware | >= 6.7.0.0 < 6.7.8.1 | 6.7.8.1 |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
Shopware vulnerable to a potential take over of app credentials
osv·2026-03-11
CVE-2026-31889 [HIGH] Shopware vulnerable to a potential take over of app credentials
Shopware vulnerable to a potential take over of app credentials
### Summary
We identified and fixed a vulnerability in the Shopware app registration flow that could, under specific conditions, allow attackers to take over the communication channel between a shop and an app. By abusing app re‑registration, an attacker could redirect app traffic to an attacker‑controlled domain and potentially obtain API credentials intended for the legitimate shop.
We have no evidence that this vulnerability has been exploited.
---
### Affected Scope
- All apps (public and private) that use a `registrationUrl` in their app manifest and rely on the legacy HMAC‑based registration flow.
- Both on‑premise and cloud installations are affected until updated to a fixed Shopware version or protected by the lat
GHSA
Shopware vulnerable to a potential take over of app credentials
ghsa·2026-03-11
CVE-2026-31889 [HIGH] CWE-290 Shopware vulnerable to a potential take over of app credentials
Shopware vulnerable to a potential take over of app credentials
### Summary
We identified and fixed a vulnerability in the Shopware app registration flow that could, under specific conditions, allow attackers to take over the communication channel between a shop and an app. By abusing app re‑registration, an attacker could redirect app traffic to an attacker‑controlled domain and potentially obtain API credentials intended for the legitimate shop.
We have no evidence that this vulnerability has been exploited.
---
### Affected Scope
- All apps (public and private) that use a `registrationUrl` in their app manifest and rely on the legacy HMAC‑based registration flow.
- Both on‑premise and cloud installations are affected until updated to a fixed Shopware version or protected by the lat
No detection rules found.
No public exploits indexed.
2026-03-11
Published