CVE-2026-31888
Shopware is an open commerce platform. Prior to 6.7.8.1 and 6.6.10.15, the Store API login endpoint (POST /store-api/account/login) returns different error codes depending on whether the submitted email address belongs to a registered customer (CHECKOUT__CUSTOMER_AUTH_BAD_CREDENTIALS) or is unknown (CHECKOUT__CUSTOMER_NOT_FOUND). The "not found" response also echoes the probed email address. This allows an unauthenticated attacker to enumerate valid customer accounts. The storefront login controller correctly unifies both error paths, but the Store API does not — indicating an inconsistent defense. This vulnerability is fixed in 6.7.8.1 and 6.6.10.15.
CVSS
- Versión: 3.1
- Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
- Puntuación base: 5.3
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.34%
- Percentil entre todas las CVEs puntuadas: 26
- Fecha de la puntuación: 6/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (1)
CWE
- CWE-204
Referencias
JSON original (NVD)
Mostrar
{
"id": "CVE-2026-31888",
"cveTags": [],
"metrics": {
"ssvcV203": [
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"ssvcData": {
"id": "CVE-2026-31888",
"role": "CISA Coordinator",
"options": [
{
"exploitation": "none"
},
{
"automatable": "no"
},
{
"technicalImpact": "partial"
}
],
"version": "2.0.3",
"timestamp": "2026-03-12T20:02:39.331863Z"
}
}
],
"cvssMetricV31": [
{
"type": "Secondary",
"source": "security-advisories@github.com",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 5.3,
"attackVector": "NETWORK",
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N",
"integrityImpact": "NONE",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "NONE",
"privilegesRequired": "NONE",
"confidentialityImpact": "LOW"
},
"impactScore": 1.4,
"exploitabilityScore": 3.9
}
]
},
"affected": [
{
"source": "security-advisories@github.com",
"affectedData": [
{
"vendor": "shopware",
"product": "core",
"versions": [
{
"status": "affected",
"version": ">= 6.7.0.0, < 6.7.8.1"
},
{
"status": "affected",
"version": "< 6.6.10.15"
}
]
},
{
"vendor": "shopware",
"product": "platform",
"versions": [
{
"status": "affected",
"version": ">= 6.7.0.0, < 6.7.8.1"
},
{
"status": "affected",
"version": "< 6.6.10.14"
}
]
}
]
}
],
"published": "2026-03-11T19:16:05.113",
"references": [
{
"url": "https://github.com/shopware/shopware/security/advisories/GHSA-gqc5-xv7m-gcjq",
"tags": [
"Vendor Advisory"
],
"source": "security-advisories@github.com"
}
],
"vulnStatus": "Analyzed",
"weaknesses": [
{
"type": "Secondary",
"source": "security-advisories@github.com",
"description": [
{
"lang": "en",
"value": "CWE-204"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "Shopware is an open commerce platform. Prior to 6.7.8.1 and 6.6.10.15, the Store API login endpoint (POST /store-api/account/login) returns different error codes depending on whether the submitted email address belongs to a registered customer (CHECKOUT__CUSTOMER_AUTH_BAD_CREDENTIALS) or is unknown (CHECKOUT__CUSTOMER_NOT_FOUND). The \"not found\" response also echoes the probed email address. This allows an unauthenticated attacker to enumerate valid customer accounts. The storefront login controller correctly unifies both error paths, but the Store API does not — indicating an inconsistent defense. This vulnerability is fixed in 6.7.8.1 and 6.6.10.15."
},
{
"lang": "es",
"value": "Shopware es una plataforma de comercio abierta. Antes de las versiones 6.7.8.1 y 6.6.10.15, el endpoint de inicio de sesión de la Store API (POST /store-api/account/login) devuelve diferentes códigos de error dependiendo de si la dirección de correo electrónico enviada pertenece a un cliente registrado (CHECKOUT__CUSTOMER_AUTH_BAD_CREDENTIALS) o es desconocida (CHECKOUT__CUSTOMER_NOT_FOUND). La respuesta de 'no encontrado' también hace eco de la dirección de correo electrónico probada. Esto permite a un atacante no autenticado enumerar cuentas de clientes válidas. El controlador de inicio de sesión del storefront unifica correctamente ambas rutas de error, pero la Store API no lo hace — lo que indica una defensa inconsistente. Esta vulnerabilidad está corregida en las versiones 6.7.8.1 y 6.6.10.15."
}
],
"lastModified": "2026-06-17T10:34:42.087",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:shopware:shopware:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "C5486B22-79CE-4581-BD61-4CF0E3BFB843",
"versionEndExcluding": "6.6.10.15"
},
{
"criteria": "cpe:2.3:a:shopware:shopware:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "A198E1E6-E6EE-4D98-BF25-E2A5055E8DC8",
"versionEndExcluding": "6.7.8.1",
"versionStartIncluding": "6.7.0.0"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "security-advisories@github.com"
}