CVE-2026-108697
Received Received - Intake

Missing Authorization in CoreShop Backend Exposes Sensitive Data

Vulnerability report for CVE-2026-108697, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-11

Last updated on: 2026-10-11

Assigner: VulnCheck

Description

CoreShop through 2026.2.2 contains a missing authorization vulnerability that allows low-privileged backend users to list permission-restricted resources because ResourceController listAction skips the isGrantedOr403() check. Authenticated Pimcore users lacking resource permissions can request the generated list routes to enumerate payment providers, carriers, price rules, stores, and tax rules including ids, names, and identifiers.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-11
Last Modified
2026-10-11
Generated
2026-10-11
AI Q&A
2026-10-11
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
CoreShop CoreShop 0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-862 The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

CoreShop through 2026.2.2 has a missing authorization vulnerability where low-privileged backend users can list permission-restricted resources. The ResourceController listAction skips the isGrantedOr403() check, allowing authenticated Pimcore users without proper permissions to enumerate sensitive data like payment providers, carriers, price rules, stores, and tax rules including their IDs, names, and identifiers.

Detection Guidance

Check for unauthorized access to restricted resource endpoints in CoreShop logs. Monitor for requests to list routes like /admin/payment-providers, /admin/carriers, /admin/price-rules, /admin/stores, or /admin/tax-rules by low-privileged users.

Impact Analysis

This vulnerability allows unauthorized users to access and enumerate restricted resources, potentially exposing sensitive business data such as payment details, tax rules, and store information. It could lead to data leaks, unauthorized modifications, or further exploitation of the system.

Compliance Impact

This vulnerability could violate compliance requirements by exposing sensitive data to unauthorized users, potentially leading to breaches of GDPR (data protection) or HIPAA (health information privacy). Unauthorized access to payment or customer data may result in regulatory penalties and reputational damage.

Mitigation Strategies

Update CoreShop to version 2026.2.2 or later. Review and restrict backend user permissions to ensure only authorized users can access sensitive resource listings. Implement additional access controls on list routes.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-108697. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart