PHP Closure Vulnerability in Shopware E-Commerce Platform
CVE-2026-23498
7.2HIGH
What is CVE-2026-23498?
Shopware, an open-source e-commerce platform, is affected by a regression vulnerability affecting versions 6.7.0.0 through prior to 6.7.6.1. This issue allows for unmet security checks against an allow list for PHP Closures when the map(...) override is manipulated with crafted arrays. Users should update to version 6.7.6.1 or later to mitigate this risk.
Affected Version(s)
shopware >= 6.7.0.0, < 6.7.6.1
