CVE-2026-23498

Shopware is an open commerce platform. From 6.7.0.0 to before 6.7.6.1, a regression of CVE-2023-2017 leads to an array and array crafted PHP Closure not checked being against allow list for the map(...) override. This vulnerability is fixed in 6.7.6.1.
Configurations

No configuration.

History

14 Jan 2026, 19:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-01-14 19:16

Updated : 2026-01-16 15:55


NVD link : CVE-2026-23498

Mitre link : CVE-2026-23498

CVE.ORG link : CVE-2026-23498


JSON object : View

Products Affected

No product.

CWE
CWE-94

Improper Control of Generation of Code ('Code Injection')