3.7
/ 10
LOW
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N
Description
Shopware is an open commerce platform. Prior to versions 6.6.10.18 and 6.7.10.1, an attacker is able to enumerate the usernames of administrator users by performing a timing attack. Versions 6.6.10.18 and 6.7.10.1 fix the issue.
Basic Information
ID
CVE-2026-48011
Source
GitHub_M
Published
Jun 10, 2026 at 20:07
Affected Product
Vendor
shopware
Product
shopware
Version
>= 6.7.0.0, < 6.7.10.1
Affected Versions
shopware shopware >= 6.7.0.0, < 6.7.10.1
shopware shopware < 6.6.10.18
shopware shopware < 6.6.10.18