
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-31889 is an authentication bypass vulnerability in Shopware's app registration flow, classified as "Potential take over of app credentials" (GHSA-c4p7-rwrg-pf6p). It affects Shopware versions prior to 6.6.10.15 (all 6.6.x releases) and versions 6.7.0.0 through 6.7.8.1 (6.7.x branch), covering both shopware/core and shopware/platform Composer packages. The vulnerability was disclosed on March 11, 2026, by Shopware's security team via GitHub Advisory. It carries a CVSS v3.1 base score of 8.9 (High) (GitHub Advisory, Shopware Advisory).
The root cause is classified as CWE-290 (Authentication Bypass by Spoofing). The legacy Shopware app registration flow used HMAC-based authentication that did not sufficiently bind a shop installation to its original domain — during re-registration, the shop-url parameter could be updated without requiring proof of control over the previously registered shop or domain (Shopware Advisory). An attacker who already possesses the relevant app-side secret can submit a crafted re-registration request substituting an attacker-controlled domain, bypassing the domain-binding check entirely. The attack is network-based, requires no privileges or user interaction, but does require prior knowledge of the app-side secret (hence High attack complexity). The vulnerability is scoped to the app system's registration and re-registration mechanism and does not affect core storefront or administration authentication (GitHub Advisory).
A successful exploit allows an attacker to redirect app-to-shop communication to an attacker-controlled domain, intercept and tamper with that traffic ("data poisoning"), and obtain API integration credentials with the full permissions granted to the compromised app (Shopware Advisory). Both on-premise and cloud Shopware installations are affected, and all apps — public and private — that use a registrationUrl in their app manifest and rely on the legacy HMAC-based registration flow are in scope. The attack typically manifests as app malfunction rather than an obvious security breach, making detection difficult for shop owners and app manufacturers, and increasing the risk of prolonged credential exposure (GitHub Advisory).
There is no public proof-of-concept exploit and no evidence of in-the-wild exploitation as of the disclosure date (Shopware Advisory). The EPSS score is approximately 0.094% (26th percentile), indicating a low near-term exploitation probability (GitHub Advisory). The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Exploitation requires prior knowledge of the app-side secret, which limits the attacker pool but does not eliminate risk for actors who have obtained secrets through other means.
shop-url parameter with an attacker-controlled domain and signing the request with the known app-side secret.shop-url.shop-url now pointing to the attacker's infrastructure, all subsequent app-to-shop communication (including API credential exchanges) is routed through the attacker-controlled domain.shop-url to an unfamiliar or external domain; re-registration log entries lacking a corresponding confirmation flow completion.shop-url values in the Shopware database for installed apps that do not correspond to authorized updates or app upgrades (Shopware Advisory).Shopware has released patched versions 6.6.10.15 and 6.7.8.1 that harden the app registration and re-registration process by requiring dual signatures (both app secret and existing shop secret), enforcing mandatory secret rotation on re-registration, and adding stricter URL validation and improved logging (Shopware Advisory). Operators unable to upgrade immediately should install or update the Shopware Security Plugin, which provides a hotfix for supported older versions. Additionally, all installed apps should be updated to their latest versions, and any suspected compromised keys should trigger app re-installation or key rotation. App manufacturers should update to the latest Shopware PHP/JS app SDKs and validate both shopware-app-signature and shopware-shop-signature on re-registration requests (GitHub Advisory).
The vulnerability was published by Shopware's security team (mkraeml) on March 11, 2026, with a detailed advisory emphasizing that no exploitation evidence existed at time of disclosure (Shopware Advisory). Coverage appeared on threat intelligence aggregators including CIRCL, VulDB, and CVEFeed shortly after disclosure, and The Hacker Wire published an article on the app registration channel hijacking issue (The Hacker Wire). Community discussion was noted on Bluesky and developer platforms such as dev.to, reflecting moderate awareness within the e-commerce and PHP developer communities.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."