{"id":"CVE-2026-31887","aliases":["GHSA-7vvp-j573-5584"],"title":"Shopware: Unauthenticated data extraction possible through store-api.order endpoint","summary":"Shopware: Unauthenticated data extraction possible through store-api.order endpoint","severity":"high","cwe":["CWE-863"],"vendor":"shopware","product":"shopware/core","ecosystem":"composer","affected":["shopware/core >= 6.7.0.0, < 6.7.8.1","shopware/core < 6.6.10.15","shopware/platform >= 6.7.0.0, < 6.7.8.1","shopware/platform < 6.6.10.15"],"patched":["shopware/core 6.7.8.1","shopware/core 6.6.10.15","shopware/platform 6.7.8.1","shopware/platform 6.6.10.15"],"published":"2026-03-11","updated":"2026-09-10","sourceUpdated":"2026-09-10T07:05:34Z","source":"GHSA","sourceUrl":"https://github.com/advisories/GHSA-7vvp-j573-5584","references":[{"url":"https://github.com/shopware/shopware/security/advisories/GHSA-7vvp-j573-5584"},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-31887"},{"url":"https://github.com/advisories/GHSA-7vvp-j573-5584"}],"tags":["ghsa","composer"],"epss":0.00394,"epssPercentile":0.30742,"ingestedAt":"2026-09-10T07:40:24.113Z","slug":"CVE-2026-31887","body":"## Overview\n\n### Summary\n\nAn insufficient check on the filter types for unauthenticated customers allows access to orders of other customers. This is part of the `deepLinkCode` support on the `store-api.order` endpoint.\n\n### Details\n\n#### Data Exposure\n\nDepending on the order payload configuration, attackers may retrieve:\n- Customer names\n- Billing address\n- Shipping address\n- Email addresses\n- Ordered products\n- Order values\n- Order numbers\n- Order dates\n- Payment method information\n- Shipping method information\n- More customs, depending on the given associations in the request\n\n#### Security Impact\n\nThis vulnerability allows:\n- Unauthorized access to foreign customer order data\n- Mass enumeration of recent orders\n- Potential scraping of customer personal information\n\n#### Limitation\n\nNo limitation, but only orders from the past 30 days are checked for changeable means of payment (unrelated).\n\n### Impact\n\nThe code is present since ~2021. Likely every version since then is impacted for every store.\n\n## Affected packages\n\n- `shopware/core >= 6.7.0.0, < 6.7.8.1`\n- `shopware/core < 6.6.10.15`\n- `shopware/platform >= 6.7.0.0, < 6.7.8.1`\n- `shopware/platform < 6.6.10.15`\n\n## Remediation\n\nUpgrade to a patched release:\n\n- `shopware/core 6.7.8.1`\n- `shopware/core 6.6.10.15`\n- `shopware/platform 6.7.8.1`\n- `shopware/platform 6.6.10.15`","depth":"twilight","depthScore":41,"depthScoreParts":{"impact":41.3,"likelihood":0.1,"exploitation":0,"ransomware":0},"changes":[]}