What is CVE-2026-48013?
This vulnerability in Shopware's `/api/_action/media/external-link` endpoint allows authenticated admin users to make server-side HTTP HEAD requests to arbitrary internal IP addresses. It can be exploited for SSRF attacks. Updating to versions 6.6.10.18 or 6.7.10.1 is recommended.
Azərbaycanca: Bu boşluq Shopware platformasında `/api/_action/media/external-link` endpoint vasitəsilə autentifikasiya olunmuş admin istifadəçilərə daxili IP ünvanlara server-tərəfli HTTP HEAD sorğuları göndərməyə imkan verir. Bu SSRF hücumları üçün istifadə oluna bilər. Shopware-nı 6.6.10.18 və ya 6.7.10.1 versiyalarına yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-918
FAQ2
Under what conditions can CVE-2026-48013 be exploited?
To exploit this vulnerability, the attacker must be an authenticated admin user on the Shopware platform.
What security issue can CVE-2026-48013 lead to?
This vulnerability can be exploited for SSRF attacks against internal IP addresses via server-side HTTP HEAD requests.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.