CVE-2026-48011 - Shopware: Timing-attack on admin panel allowing enumeration of administrator usernames
CVE ID :CVE-2026-48011
Published : June 10, 2026, 10:17 p.m. | 1 hour, 13 minutes ago
Description :Shopware is an open commerce platform. Prior to versions 6.6.10.18 and 6.7.10.1, an attacker is able to enumerate the usernames of administrator users by performing a timing attack. Versions 6.6.10.18 and 6.7.10.1 fix the issue.
Severity: 3.7 | LOW
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
Published : June 10, 2026, 10:17 p.m. | 1 hour, 13 minutes ago
Description :Shopware is an open commerce platform. Prior to versions 6.6.10.18 and 6.7.10.1, an attacker is able to enumerate the usernames of administrator users by performing a timing attack. Versions 6.6.10.18 and 6.7.10.1 fix the issue.
Severity: 3.7 | LOW
Visit the link for more details, such as CVSS details, affected products, timeline, and more...