Sansec logo

Shopware fixes Store API vulnerability allowing administrator takeover

Sansec

by Sansec Forensics Team

Published in Threat Research − August 25, 2026

A Shopware vulnerability can lead to administrator takeover and remote code execution. Shopware merchants should install the security update now.

Shopware fixes Store API vulnerability allowing administrator takeover

Shopware merchants should update to 6.7.13.1 or 6.6.10.23 immediately. Sansec discovered and confirmed the vulnerability in Shopware 6.7.12.2, the latest stable release at the time of testing.

An attacker can exploit the flaw to take over an administrator account and execute PHP on the Shopware server. The attack needs an active Sales Channel key. Headless storefronts expose this key to clients as part of normal operation.

Affected versions

VersionStatus
Shopware 6.7.0.0 through 6.7.13.0Vulnerable
Shopware versions before 6.6.10.23Vulnerable
Shopware 6.7.13.1Fixed
Shopware 6.6.10.23Fixed

Shopware rates the vulnerability High (CVSS 8.6): CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N

Shopware advisories:

What merchants should do now

  1. Update Shopware to one of the fixed releases listed above or restrict access to the Store API where feasible.
  2. Run eComscan to check for vulnerable Shopware code, malicious plugins and modified PHP files.
  3. After updating, review password recovery activity, remove suspicious administrator accounts, reset passwords and revoke unknown OAuth tokens.
  4. Review all installed plugins and the Shopware filesystem for code that your team did not deploy.

Scaling vulnerability research

This finding is part of a broader Sansec effort. We have been working around the clock to find and triage vulnerabilities in ecommerce platforms, and new AI-assisted research capabilities now let us cover far more code, far faster. Expect more disclosures from this program.

Disclosure timeline

DateEvent
2026-07-22Sansec discovered the vulnerability and began validation.
2026-07-24Sansec reported the vulnerability to Shopware.
2026-07-27Shopware acknowledged the report.
2026-08-25Shopware released versions 6.7.13.1 and 6.6.10.23.
2026-08-25Sansec published this security advisory.

Read more

Scan your store now
for malware & vulnerabilities

$ curl ecomscan.com | sh

eComscan is the most thorough security scanner for Magento, Adobe Commerce, Shopware, WooCommerce, Sylius and many more.

Stay up to date with the latest eCommerce attacks

Sansec logo

experts in eCommerce security

Terms & Conditions
Privacy & Cookie Policy