Server-side Request Forgery Vulnerability in Shopware Platform
CVE-2026-48013

4.1MEDIUM

Key Information:

Vendor

Shopware

Vendor
CVE Published:
23 July 2026

What is CVE-2026-48013?

In Shopware, a server-side request forgery (SSRF) vulnerability exists that allows authenticated admin users to perform HTTP HEAD requests to internal IP addresses via the /api/_action/media/external-link endpoint. The vulnerability arises because the linkURL flow bypasses essential validation on target IP addresses, only checking for basic URL formatting, thus exposing internal network services and cloud metadata endpoints to potential exploitation. This issue is addressed in the versions 6.6.10.18 and 6.7.10.1.

Affected Version(s)

platform < 6.6.10.18 < 6.6.10.18

platform >= 6.7.0.0, < 6.7.10.1 < 6.7.0.0, 6.7.10.1

shopware < 6.6.10.18 < 6.6.10.18

References

CVSS V3.1

Score:
4.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.