LIVE · cybersecurity feed
Live wire
cve recordhigh

CVE-2026-31889

shopware · shopware

Published
CVSS8.9
Severityhigh
WeaknessCWE-290
ExploitedNot in CISA KEV

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:L

Description

Shopware is an open commerce platform. Prior to 6.6.10.15 and 6.7.8.1, a vulnerability in the Shopware app registration flow that could, under specific conditions, allow attackers to take over the communication channel between a shop and an app. The legacy app registration flow used HMAC‑based authentication without sufficiently binding a shop installation to its original domain. During re‑registration, the shop-url could be updated without proving control over the previously registered shop or domain. This made targeted hijacking of app communication feasible if an attacker possessed the relevant app‑side secret. By abusing app re‑registration, an attacker could redirect app traffic to an a

References

← Back to the CVE Tracker

Our coverage of CVE-2026-31889

No stories yet. This page updates automatically when we publish reporting that references CVE-2026-31889.