Information Exposure in Shopware Open Commerce Platform
CVE-2026-32142
5.3MEDIUM
What is CVE-2026-32142?
An information exposure vulnerability exists in the Shopware Open Commerce Platform, specifically within the /api/_info/config endpoint. This flaw allows unauthorized access to sensitive information regarding license details, potentially enabling an attacker to exploit critical system aspects. Users are advised to upgrade to Shopware version 7.8.1 or 6.10.15 to mitigate this issue.
Affected Version(s)
commercial >= 7.0.0, < 7.8.1 < 7.0.0, 7.8.1
commercial < 6.10.15 < 6.10.15
