<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Wed, 07 Oct 2026 06:05:46 +0000</lastBuildDate>
    <item>
      <title>EUVD-2026-326643</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-326643</link>
      <description>EUVD-2026-326643</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-326643</guid>
    </item>
    <item>
      <title>fkie_cve-2026-48011</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-48011</link>
      <description>&lt;p&gt;Shopware is an open commerce platform. Prior to versions 6.6.10.18 and 6.7.10.1, an attacker is able to enumerate the usernames of administrator users by performing a timing attack. Versions 6.6.10.18 and 6.7.10.1 fix the issue.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Shopware is an open commerce platform. Prior to versions 6.6.10.18 and 6.7.10.1, an attacker is able to enumerate the usernames of administrator users by performing a timing attack. Versions 6.6.10.18 and 6.7.10.1 fix the issue.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-48011</guid>
    </item>
    <item>
      <title>GHSA-7w52-7jvm-m9vw — Shopware: Timing-attack on admin panel allowing enumeration of administrator usernames</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-7w52-7jvm-m9vw</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Packagist: shopware/platform, Packagist: shopware/core&lt;/p&gt;
&lt;p&gt;### Summary
There is a Proof of Concept which is able to enumerate the usernames of administrator users. This was possible by performing a timing attack.&lt;/p&gt;
&lt;p&gt;### Details
The faulty code exists in [`src/Core/Framework/Api/OAuth/UserRepository.php`](https://github.com/shopware/shopware/blob/trunk/src/Core/Framework/Api/OAuth/UserRepository.php):
```
public function getUserEntityByUserCredentials(
        string $username,
        #[\SensitiveParameter]
        string $password,
        string $grantType,
        ClientEntityInterface $clientEntity
    ): ?UserEntityInterface {
        if ($this-&amp;gt;loginConfigService-&amp;gt;getConfig()?-&amp;gt;useDefault === false) {
            // never allow login via password if the default login is disabled (e.g. using SSO only)
            return null;
        }&lt;/p&gt;
&lt;p&gt;$builder = $this-&amp;gt;connection-&amp;gt;createQueryBuilder();
        $user = $builder-&amp;gt;select(&amp;#39;user.id&amp;#39;, &amp;#39;user.password&amp;#39;)
            -&amp;gt;from(&amp;#39;user&amp;#39;)
            -&amp;gt;where(&amp;#39;username = :username&amp;#39;)
            -&amp;gt;setParameter(&amp;#39;username&amp;#39;, $username)
            -&amp;gt;fetchAssociative();&lt;/p&gt;
&lt;p&gt;// PATH 1: EARLY RETURN WHEN USERNAME IS NOT FOUND
        if (!$user) {
            return null;
        }&lt;/p&gt;
&lt;p&gt;// PATH 2: VERIFY PASSWORD IF USER IS FOUND
        if (!password_verify($password, (string) $user[&amp;#39;password&amp;#39;])) {
            return null;
        }&lt;/p&gt;
&lt;p&gt;return new User(Uuid::fromBytesToHex($user[&amp;#39;id&amp;#39;]));
    }
```&lt;/p&gt;
&lt;p&gt;Subroutine `getUserEntityByUserCredentials()` is called when an auth request is se…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Packagist: shopware/platform, Packagist: shopware/core&lt;/p&gt;
&lt;p&gt;### Summary
There is a Proof of Concept which is able to enumerate the usernames of administrator users. This was possible by performing a timing attack.&lt;/p&gt;
&lt;p&gt;### Details
The faulty code exists in [`src/Core/Framework/Api/OAuth/UserRepository.php`](https://github.com/shopware/shopware/blob/trunk/src/Core/Framework/Api/OAuth/UserRepository.php):
```
public function getUserEntityByUserCredentials(
        string $username,
        #[\SensitiveParameter]
        string $password,
        string $grantType,
        ClientEntityInterface $clientEntity
    ): ?UserEntityInterface {
        if ($this-&amp;gt;loginConfigService-&amp;gt;getConfig()?-&amp;gt;useDefault === false) {
            // never allow login via password if the default login is disabled (e.g. using SSO only)
            return null;
        }&lt;/p&gt;
&lt;p&gt;$builder = $this-&amp;gt;connection-&amp;gt;createQueryBuilder();
        $user = $builder-&amp;gt;select(&amp;#39;user.id&amp;#39;, &amp;#39;user.password&amp;#39;)
            -&amp;gt;from(&amp;#39;user&amp;#39;)
            -&amp;gt;where(&amp;#39;username = :username&amp;#39;)
            -&amp;gt;setParameter(&amp;#39;username&amp;#39;, $username)
            -&amp;gt;fetchAssociative();&lt;/p&gt;
&lt;p&gt;// PATH 1: EARLY RETURN WHEN USERNAME IS NOT FOUND
        if (!$user) {
            return null;
        }&lt;/p&gt;
&lt;p&gt;// PATH 2: VERIFY PASSWORD IF USER IS FOUND
        if (!password_verify($password, (string) $user[&amp;#39;password&amp;#39;])) {
            return null;
        }&lt;/p&gt;
&lt;p&gt;return new User(Uuid::fromBytesToHex($user[&amp;#39;id&amp;#39;]));
    }
```&lt;/p&gt;
&lt;p&gt;Subroutine `getUserEntityByUserCredentials()` is called when an auth request is se…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-7w52-7jvm-m9vw</guid>
    </item>
  </channel>
</rss>
