CVE-2026-48010
published 2026-06-04CVE-2026-48010: Shopware: Privilege escalation: non-admin user with user:create ACL can create admin accounts `UserController::upsertUser()` writes user data in `SYSTEM_SCOPE`…
medium
Shopware: Privilege escalation: non-admin user with user:create ACL can create admin accounts
`UserController::upsertUser()` writes user data in `SYSTEM_SCOPE` and does not filter the `admin` field. A non-admin API user with `user:create` or `user:update` ACL permission can set `admin: true` on new or existing users, escalating to full admin access.
## The Problem
In `src/Core/Framework/Api/Controller/UserController.php`, line 210-234:
```php
public function upsertUser(?string $userId, Request $request, Context $context, ResponseFactoryInterface $factory): Response
{
$data = $request->request->all(); // raw request data, no field filtering
// ...
$events = $context->scope(Context::SYSTEM_SCOPE, fn (Context $context) =>
$this->userRepository->upsert([$data], $context)
);
}
```
`SYSTEM_SCOPE` bypasses `AclWriteValidator` entirely (line 52 of `AclWriteValidator::preValidate()` returns early for `SYSTEM_SCOPE`). The `admin` boolean field is accepted without restriction.
Compare with `IntegrationController::upsertIntegration()` in the same codebase, which correctly checks:
```php
if ((!$source instanceof AdminApiSource)
|| (!$source->isAdmin()
&& isset($data['admin']))
) {
throw new PermissionDeniedException();
}
```
`UserController` is missing this exact check.
## Impact
Any API user with the low-privilege `user:create` permission can create accounts with full admin access, or with `user:update` can promote any existing user to admin. This is a direct privilege escalation.
## Suggested Fix
Add the same `isAdmin()` check from `IntegrationController`:
```php
$source = $context->getSource();
if ((!$source instanceof AdminApiSource) || (!$source->isAdmin() && isset($data['admin']))) {
throw new PermissionDeniedException();
}
```
Best regards,
Keyvan HardaniAffected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| shopware | core | >= 0 < 6.6.10.18 | 6.6.10.18 |
| shopware | core | >= 6.7.0.0 < 6.7.10.1 | 6.7.10.1 |
| shopware | platform | >= 0 < 6.6.10.18 | 6.6.10.18 |
| shopware | platform | >= 6.7.0.0 < 6.7.10.1 | 6.7.10.1 |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2026-06-04
Published