shopware/core is vulnerable to Privilege Escalation
65
Medium Risk
Shopware's Administration user-update path still allowed mass assignment of nested aclRoles after CVE-2026-48010 blocked the admin flag. An authenticated Administration user with permission to update users can attach extra ACL roles through that write and gain privileges beyond those originally granted, including administrative capabilities. The patch validates nested ACL role writes so generic Admin API writes cannot create or update acl_role entities outside authorized controllers.
You are affected if you are using a version that falls within the vulnerable range and Administration users have permission to update other users.
shopware/core is vulnerable to Privilege Escalation in versions 6.7.0.0 - 6.7.13.0 and 6.0.0.0 - 6.6.10.22.
Upgrade the shopware/core and/or the shopware/platform library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant