CVE-2026-48011

Shopware is an open commerce platform. Prior to versions 6.6.10.18 and 6.7.10.1, an attacker is able to enumerate the usernames of administrator users by performing a timing attack. Versions 6.6.10.18 and 6.7.10.1 fix the issue.
Configurations

No configuration.

History

11 Jun 2026, 16:16

Type Values Removed Values Added
References () https://github.com/shopware/shopware/security/advisories/GHSA-7w52-7jvm-m9vw - () https://github.com/shopware/shopware/security/advisories/GHSA-7w52-7jvm-m9vw -

10 Jun 2026, 22:17

Type Values Removed Values Added
New CVE

Information

Published : 2026-06-10 22:17

Updated : 2026-06-11 16:16


NVD link : CVE-2026-48011

Mitre link : CVE-2026-48011

CVE.ORG link : CVE-2026-48011


JSON object : View

Products Affected

No product.

CWE
CWE-208

Observable Timing Discrepancy