Shopware fixes Store API vulnerability allowing administrator takeover
by Sansec Forensics Team
Published in Threat Research − August 25, 2026
A Shopware vulnerability can lead to administrator takeover and remote code execution. Shopware merchants should install the security update now.

Shopware merchants should update to 6.7.13.1 or 6.6.10.23 immediately. Sansec discovered and confirmed the vulnerability in Shopware 6.7.12.2, the latest stable release at the time of testing.
An attacker can exploit the flaw to take over an administrator account and execute PHP on the Shopware server. The attack needs an active Sales Channel key. Headless storefronts expose this key to clients as part of normal operation.
Affected versions
| Version | Status |
|---|---|
| Shopware 6.7.0.0 through 6.7.13.0 | Vulnerable |
| Shopware versions before 6.6.10.23 | Vulnerable |
| Shopware 6.7.13.1 | Fixed |
| Shopware 6.6.10.23 | Fixed |
Shopware rates the vulnerability High (CVSS 8.6): CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N
Shopware advisories:
What merchants should do now
- Update Shopware to one of the fixed releases listed above or restrict access to the Store API where feasible.
- Run eComscan to check for vulnerable Shopware code, malicious plugins and modified PHP files.
- After updating, review password recovery activity, remove suspicious administrator accounts, reset passwords and revoke unknown OAuth tokens.
- Review all installed plugins and the Shopware filesystem for code that your team did not deploy.
Scaling vulnerability research
This finding is part of a broader Sansec effort. We have been working around the clock to find and triage vulnerabilities in ecommerce platforms, and new AI-assisted research capabilities now let us cover far more code, far faster. Expect more disclosures from this program.
Disclosure timeline
| Date | Event |
|---|---|
| 2026-07-22 | Sansec discovered the vulnerability and began validation. |
| 2026-07-24 | Sansec reported the vulnerability to Shopware. |
| 2026-07-27 | Shopware acknowledged the report. |
| 2026-08-25 | Shopware released versions 6.7.13.1 and 6.6.10.23. |
| 2026-08-25 | Sansec published this security advisory. |
Read more
In this article
Protect your store now!
Block all known Magento attacks, while you schedule the latest critical patch until a convenient moment. No more downtime and instability from rushed patching.
Get Sansec ShieldScan your store now
for malware & vulnerabilities
eComscan is the most thorough security scanner for Magento, Adobe Commerce, Shopware, WooCommerce, Sylius and many more.
Learn more