CVE-2026-48012 | Shopware up to 6.7.10.0 SSO Entry Point /api/oauth/sso/auth Referer redirect

SecurityVulns

A vulnerability was found in Shopware up to 6.7.10.0. It has been rated as problematic. The affected element is an unknown function of the file /api/oauth/sso/auth of the component SSO Entry Point. This manipulation of the argument Referer causes open redirect.

This vulnerability is registered as CVE-2026-48012. Remote exploitation of the attack is possible. No exploit is available.

Upgrading the affected component is advised.VulDB Recent EntriesRead More