
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-31887 is an incorrect authorization vulnerability in Shopware, an open-source e-commerce platform, that allows unauthenticated attackers to access order data belonging to other customers. The flaw exists in the store-api.order endpoint's deepLinkCode support, where filter types are insufficiently validated for unauthenticated requests. It affects Shopware versions >= 6.7.0.0 and < 6.7.8.1, as well as all versions < 6.6.10.15. The vulnerability was disclosed on March 11, 2026, and carries a CVSS v3.1 score of 7.5 (High) and a CVSS v4.0 score of 8.9 (High) (GitHub Advisory, Github Advisory).
The root cause is classified as CWE-863 (Incorrect Authorization): the store-api.order endpoint does not properly validate filter types when processing requests from unauthenticated users leveraging the deepLinkCode feature, allowing them to bypass access controls intended to restrict order visibility to the owning customer. An attacker can craft API requests to the endpoint with manipulated filter parameters to retrieve orders belonging to arbitrary customers. The advisory notes the vulnerable code has been present since approximately 2021, suggesting a broad historical exposure window across many Shopware versions (GitHub Advisory, Github Advisory).
Successful exploitation enables unauthenticated, remote attackers to enumerate and extract sensitive customer order data from affected Shopware stores, including customer names, billing and shipping addresses, email addresses, ordered products, order values, order numbers, order dates, and payment and shipping method information. The vulnerability supports mass enumeration of recent orders and potential scraping of personally identifiable information (PII) at scale, posing significant privacy and regulatory compliance risks for store operators. There is no impact on integrity or availability, but the confidentiality impact is rated High for both the vulnerable and subsequent systems (GitHub Advisory).
No public proof-of-concept exploit code has been identified, and there is no evidence of active in-the-wild exploitation at the time of disclosure (Feedly). The vulnerability requires no authentication, no user interaction, and has low attack complexity, making it straightforward to exploit if targeted. The EPSS score is approximately 0.041% (16th percentile), indicating a currently low but non-negligible probability of exploitation within 30 days. The CVE is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog (Github Advisory).
store-api.order endpoint (typically accessible at /store-api/order) which supports deepLinkCode-based unauthenticated access.store-api.order endpoint with manipulated filter parameters that bypass the insufficient filter-type validation, omitting or substituting the expected customer-scoping filter./store-api/order from a single IP or rotating IP ranges; requests containing unexpected or broad filter parameters not typical of normal customer browsing.store-api.order endpoint with varying filter values; absence of session tokens or authentication headers in requests to this endpoint.Shopware has released patched versions 6.7.8.1 (for the 6.7.x branch) and 6.6.10.15 (for the 6.6.x branch); upgrading to these versions is the primary recommended remediation (GitHub Advisory). If immediate patching is not feasible, operators should consider restricting unauthenticated access to the store-api.order endpoint at the web server or WAF level, or implementing additional authorization controls. Administrators should also review access logs to determine whether unauthorized order data access has already occurred and assess potential data breach notification obligations.
The vulnerability was published by Shopware's security team (mkraeml) via GitHub Security Advisories on March 11, 2026, with coordinated disclosure crediting reporter mromeike and coordinators ab-pknollmann and janschoepke (GitHub Advisory). A brief technical write-up was published by Infinitsec shortly after disclosure, highlighting the unauthenticated data extraction risk (Feedly). General community coverage was limited to automated CVE tracking feeds and databases, with no significant broader media or researcher commentary identified.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."