What is CVE-2026-48012?
CVE-2026-48012 is an open redirect vulnerability in Shopware's public SSO entry point at `GET /api/oauth/sso/auth`, affecting versions 6.7.3.0 through 6.7.10.0. When the required SSO session state is missing, the application falls back to the request's `Referer` header for redirection. Administrators using the affected versions should immediately update the platform or restrict the endpoint.
Azərbaycanca: CVE-2026-48012 Shopware-in 6.7.3.0-dən 6.7.10.0-a qədər versiyalarında `GET /api/oauth/sso/auth` SSO giriş nöqtəsində aşkar olunmuş "open redirect" zəifliyidir. Gözlənilən SSO session state olmadıqda, tətbiq `Referer` header-inə əsaslanaraq istifadəçini yönləndirir. Bu səbəbdən təsirlənən versiyalardan istifadə edən Shopware adminləri dərhal platformanı yeniləməli və ya göstərilən endpoint-i məhdudlaşdırmalıdır.
FAQ2
Which versions of Shopware are affected by CVE-2026-48012?
This open redirect vulnerability affects Shopware versions 6.7.3.0 through 6.7.10.0.
Which header does CVE-2026-48012 use to redirect users?
When the expected SSO session state is missing, the application relies on the `Referer` header for redirection.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.