CVE-2026-48011
Shopware: Timing-attack on admin panel allowing enumeration of administrator usernames
Shopware is an open commerce platform. Prior to versions 6.6.10.18 and 6.7.10.1, an attacker is able to enumerate the usernames of administrator users by performing a timing attack. Versions 6.6.10.18 and 6.7.10.1 fix the issue.
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N
Affected products
shopware · shopwareWant to know if your infrastructure is exposed to this?
Talk to TrueHacking →