SCA: security update for shopware/core, shopware/platform (GHSA-c4p7-rwrg-pf6p)

high Tenable Cloud Security Plugin ID 438668

Description

There are packages installed that are affected by a vulnerability referenced in the following CVE:

- Shopware is an open commerce platform. Prior to 6.6.10.15 and 6.7.8.1, a vulnerability in the Shopware app
registration flow that could, under specific conditions, allow attackers to take over the communication
channel between a shop and an app. The legacy app registration flow used HMAC‑based authentication without
sufficiently binding a shop installation to its original domain. During re‑registration, the shop-url
could be updated without proving control over the previously registered shop or domain. This made targeted
hijacking of app communication feasible if an attacker possessed the relevant app‑side secret. By abusing
app re‑registration, an attacker could redirect app traffic to an attacker‑controlled domain and
potentially obtain API credentials intended for the legitimate shop. This vulnerability is fixed in
6.6.10.15 and 6.7.8.1. (CVE-2026-31889)

Solution

Update the shopware/core library and its related packages to version 6.6.10.15 or later.

See Also

https://github.com/advisories/GHSA-c4p7-rwrg-pf6p

Plugin Details

Severity: High

ID: 438668

Version: Revision 1.8

Type: Local

Family: SCA Checks

Published: 3/12/2026

Updated: 7/2/2026

Supported Sensors: Tenable Cloud Security, Tenable Self-Hosted Container Security

Risk Information

VPR

Risk Factor: Medium

Score: 5

Percentile: 94.39

Vendor

Vendor Severity: High

CVSS v2

Risk Factor: High

Base Score: 7.3

Temporal Score: 5.4

Vector: CVSS2#AV:N/AC:H/Au:N/C:C/I:C/A:P

CVSS Score Source: CVE-2026-31889

CVSS v3

Risk Factor: High

Base Score: 8.9

Temporal Score: 7.7

Vector: CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:L

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

Vulnerability Information

Exploit Ease: No known exploits are available

Patch Publication Date: 3/11/2026

Vulnerability Publication Date: 3/11/2026

Reference Information

CVE: CVE-2026-31889

cwe: CWE-290