cbcvebase.
CVE-2026-48010
published 2026-06-04

CVE-2026-48010: Shopware: Privilege escalation: non-admin user with user:create ACL can create admin accounts `UserController::upsertUser()` writes user data in `SYSTEM_SCOPE`…

medium
Shopware: Privilege escalation: non-admin user with user:create ACL can create admin accounts

`UserController::upsertUser()` writes user data in `SYSTEM_SCOPE` and does not filter the `admin` field. A non-admin API user with `user:create` or `user:update` ACL permission can set `admin: true` on new or existing users, escalating to full admin access.

## The Problem

In `src/Core/Framework/Api/Controller/UserController.php`, line 210-234:

```php
public function upsertUser(?string $userId, Request $request, Context $context, ResponseFactoryInterface $factory): Response
{
$data = $request->request->all(); // raw request data, no field filtering
// ...
$events = $context->scope(Context::SYSTEM_SCOPE, fn (Context $context) =>
$this->userRepository->upsert([$data], $context)
);
}
```

`SYSTEM_SCOPE` bypasses `AclWriteValidator` entirely (line 52 of `AclWriteValidator::preValidate()` returns early for `SYSTEM_SCOPE`). The `admin` boolean field is accepted without restriction.

Compare with `IntegrationController::upsertIntegration()` in the same codebase, which correctly checks:

```php
if ((!$source instanceof AdminApiSource)
|| (!$source->isAdmin()
&& isset($data['admin']))
) {
throw new PermissionDeniedException();
}
```

`UserController` is missing this exact check.

## Impact

Any API user with the low-privilege `user:create` permission can create accounts with full admin access, or with `user:update` can promote any existing user to admin. This is a direct privilege escalation.

## Suggested Fix

Add the same `isAdmin()` check from `IntegrationController`:

```php
$source = $context->getSource();
if ((!$source instanceof AdminApiSource) || (!$source->isAdmin() && isset($data['admin']))) {
throw new PermissionDeniedException();
}
```

Best regards,
Keyvan Hardani

Affected

4 ranges
VendorProductVersion rangeFixed in
shopwarecore>= 0 < 6.6.10.186.6.10.18
shopwarecore>= 6.7.0.0 < 6.7.10.16.7.10.1
shopwareplatform>= 0 < 6.6.10.186.6.10.18
shopwareplatform>= 6.7.0.0 < 6.7.10.16.7.10.1
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.