
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-23498 is a code injection vulnerability in Shopware, an open-source e-commerce platform, caused by a regression in the fix for CVE-2023-2017. The flaw affects Shopware versions 6.7.0.0 through 6.7.6.0 (inclusive), and was disclosed on January 14, 2026. It allows high-privileged authenticated attackers to bypass the Twig template engine's function allow-list by crafting array-based PHP Closures passed to the map() filter. It carries a CVSS v3.1 base score of 7.2 (High) (GitHub Advisory).
The root cause is classified as CWE-94 (Improper Control of Generation of Code / Code Injection). Shopware's TwigSecurityExtension was previously patched (CVE-2023-2017) to restrict Twig filter functions to an allow-list; however, a regression left the map() filter's callable validation incomplete — specifically, when the callable was passed as a PHP array (e.g., [ClassName::class, 'method']), it was not converted to a string before being checked against the allow-list, allowing arbitrary class methods to be invoked (GitHub Advisory). The fix in commit 3966b05 adds a check that converts array callables to their string equivalent (ClassName::method) before performing the allow-list validation (Patch Commit). Exploitation requires network access and high privileges (e.g., admin-level access to the Shopware backend where Twig templates can be edited).
Successful exploitation allows a high-privileged attacker to execute arbitrary PHP code on the server by injecting crafted Twig template content that invokes unapproved PHP functions via the map() filter. This results in full compromise of confidentiality, integrity, and availability of the affected Shopware instance, potentially enabling data exfiltration of customer and payment data, modification of storefront content, or complete server takeover (GitHub Advisory).
No public exploit code or in-the-wild exploitation has been confirmed as of the time of this report. The EPSS score is approximately 0.044%, indicating a low near-term exploitation probability (Feedly). The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Exploitation requires high privileges, which significantly limits the attack surface to compromised or malicious admin accounts. A GitHub repository (lukasz-rybak/CVE-2026-23498) appeared in January 2026, potentially containing research or PoC material, but no weaponized exploit has been confirmed (Feedly).
map() filter with an array-style PHP callable to invoke an arbitrary function not on the allow-list, e.g., {{ someArray|map(['DangerousClass', 'dangerousMethod']) }}.TwigSecurityExtension.public/ or custom/ directories; modifications to existing Twig template files with injected map() filter calls.curl, wget, bash) that are not part of normal Shopware operation.Shopware has released version 6.7.6.1 which patches this vulnerability by ensuring array-style PHP callables are converted to their string form before allow-list validation in the TwigSecurityExtension (GitHub Advisory, Patch Commit). Operators who cannot immediately upgrade should install the official Shopware security plugin as a workaround. Additionally, restricting admin panel access to trusted IP ranges and enforcing strong authentication (MFA) for admin accounts reduces the risk of exploitation.
The vulnerability was reported by researchers lukasz-rybak and andreisss, credited in the GitHub Security Advisory (GitHub Advisory). The advisory was published by Shopware maintainer mkraeml on January 14, 2026. No significant broader media coverage or notable social media discussion beyond standard CVE tracking feeds has been observed.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."