CVE-2026-31887
Shopware is an open commerce platform. Prior to 6.7.8.1 and 6.6.10.15, an insufficient check on the filter types for unauthenticated customers allows access to orders of other customers. This is part of the deepLinkCode support on the store-api.order endpoint. This vulnerability is fixed in 6.7.8.1 and 6.6.10.15.
- Affected products
- Core, Xplatform, Shopware, Shopware/Core, Shopware/Platform
- Shopware
- < 6.6.10.15, 6.7.8.1
- Fix
- Available
- CVSS 4.0
- 8.9 HIGH
- CVSS 3.1
- 7.5 HIGH
- EPSS
- 0.2% (15th percentile)
- Weakness
- CWE-863
- NVD status
- Analyzed
- Published
- 2026-03-11
CVE-2026-31887 at NVD
No indexed exploits for CVE-2026-31887 yet
Our index is partial: it proves presence, never absence
No exploit for CVE-2026-31887 has been indexed yet. Our index is built from live traffic and upstream syncs, so this page can only say what it knows — not that no exploit exists.