PT-2026-2949 · Shopware · Shopware

Lukasz-Rybak

·

Published

2026-01-14

·

Updated

2026-01-28

·

CVE-2026-23498

CVSS v3.1

7.2

High

VectorAV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Shopware versions 6.7.0.0 through 6.7.6.0
Description The software contains a flaw due to a regression of a previous fix, allowing the execution of unchecked PHP Closures within the map() override function. This could potentially lead to remote code execution. The issue stems from an insufficient allow list check for PHP Closures used in the map() function.
Recommendations Update to version 6.7.6.1 or later. Install the security plugin.

Exploit

Fix

RCE

Code Injection

Weakness Enumeration

Related Identifiers

CVE-2026-23498
GHSA-7CW6-7H3H-V8PF

Affected Products

Shopware