Description
Shopware is an open commerce platform. Prior to 6.6.10.18 and 6.7.10.1, a non-admin API user with integration:create ACL privilege can escalate to full administrator by creating an integration with admin: true through the Sync API POST /api/_action/sync; the regular integration endpoint POST /api/integration blocks this, but SyncController::sync() routes writes through SyncService to EntityWriter::upsert(), and src/Core/Framework/Integration/IntegrationDefinition.php lacks WriteProtection on the admin field. This issue is fixed in versions 6.6.10.18 and 6.7.10.1.
Published: 2026-07-17
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Shopware is an open commerce platform. In versions before 6.6.10.18 and 6.7.10.1, a non‑admin API user who has the integration:create ACL privilege can raise their privileges to full administrator by creating an integration that sets the admin flag to true through the Sync API POST /api/_action/sync. Although the standard integration endpoint POST /api/integration blocks such a flag change, the SyncController::sync() path bypasses this check, routing the request through SyncService to EntityWriter::upsert(). Because the IntegrationDefinition class does not provide write protection for the admin field, the request succeeds. This access‑control flaw, classified as CWE‑862, allows the attacker to permanently gain administrator rights, fully compromising the platform’s confidentiality, integrity, and availability.

Affected Systems

Shopware Platform and Shopware eCommerce Platform versions prior to 6.6.10.18 and 6.7.10.1 are affected. Integration creation through the Sync API in those releases can be abused to elevate privileges. The issue was addressed and fixed in the 6.6.10.18 and 6.7.10.1 releases.

Risk and Exploitability

The CVSS score of 6.5 indicates a moderate severity. The EPSS score is listed as < 1%, implying a very low probability of exploitation at the time of reporting. The vulnerability is not currently listed in the CISA KEV catalog. Likely exploitation requires authentic API access with the integration:create privilege, and the attack would be conducted remotely by sending crafted POST requests to the Sync endpoint. If an attacker already has limited API rights, the vulnerability can be leveraged to elevate to full administrator status.

Generated by OpenCVE AI on July 30, 2026 at 23:57 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the Shopware patch v6.6.10.18 or v6.7.10.1 to eliminate the admin flag bypass.
  • Restrict the integration:create ACL privilege to trusted users or disable the Sync API for untrusted roles.
  • Audit existing integrations for the admin flag and revoke any that have been granted administrator rights without proper authorization.
  • Monitor API logs for unexpected admin flag usage and inspect integration creation events for anomalies.

Generated by OpenCVE AI on July 30, 2026 at 23:57 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Github GHSA Github GHSA GHSA-gv8p-48fr-4fxg Shopware: Privilege Escalation via Sync API Integration Admin Flag Bypass
History

Fri, 17 Jul 2026 20:30:00 +0000

Type Values Removed Values Added
First Time appeared Shopware
Shopware platform
Shopware shopware
Vendors & Products Shopware
Shopware platform
Shopware shopware
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 17 Jul 2026 18:15:00 +0000

Type Values Removed Values Added
Description Shopware is an open commerce platform. Prior to 6.6.10.18 and 6.7.10.1, a non-admin API user with integration:create ACL privilege can escalate to full administrator by creating an integration with admin: true through the Sync API POST /api/_action/sync; the regular integration endpoint POST /api/integration blocks this, but SyncController::sync() routes writes through SyncService to EntityWriter::upsert(), and src/Core/Framework/Integration/IntegrationDefinition.php lacks WriteProtection on the admin field. This issue is fixed in versions 6.6.10.18 and 6.7.10.1.
Title Shopware: Privilege Escalation via Sync API Integration Admin Flag Bypass
Weaknesses CWE-862
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:N'}


Subscriptions

Shopware Platform Shopware
cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-07-17T19:47:56.823Z

Reserved: 2026-05-20T17:44:09.586Z

Link: CVE-2026-48008

cve-icon Vulnrichment

Updated: 2026-07-17T19:47:52.301Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-31T00:00:06Z

Weaknesses