Sceawere

Vulnerability Detail

CVE-2026-108697UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

CoreShop Missing Authorization Vulnerability

Vulnerability Metadata

Severity
Medium
Score / CVSS
4.3
Creation Date
3h ago
Vendor
CoreShop
Product
CoreShop
Attack Type
Missing Authorization
Vector String
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Attack Complexity
LOW

Narrative and Response

Description

CoreShop through 2026.2.2 contains a missing authorization vulnerability that allows low-privileged backend users to list permission-restricted resources because ResourceController listAction skips the isGrantedOr403() check. Authenticated Pimcore users lacking resource permissions can request the generated list routes to enumerate payment providers, carriers, price rules, stores, and tax rules including ids, names, and identifiers.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "4.3",
  "pubDate": "2026-10-11T14:17:03.973Z",
  "pubdate": "2026-10-11T14:17:03.973Z",
  "executiveSummary": "CoreShop versions through 2026.2.2 are susceptible to a missing authorization vulnerability originating from an inadequate access control implementation within the backend resource management system.\nThe vulnerability is classified as an improper access control flaw where the ResourceController fails to perform necessary permission validation.\nThis vulnerability allows authenticated backend users with low privileges to bypass intended security constraints and access sensitive administrative information that should be restricted based on their assigned roles.\nSuccessful exploitation enables unauthorized enumeration of core business configuration entities, including payment providers, shipping carriers, pricing strategies, store configurations, and tax rules.\nThe risk to the organization involves the exposure of internal operational configurations, which facilitates reconnaissance activities for further malicious actions. Exploitation requires the attacker to be an authenticated Pimcore user, though they need not possess the explicit administrative permissions typically required to view these resources.\nThis represents a failure in the principle of least privilege, as the application assumes that access to the controller implies authorization to list all constituent resources without verifying specific user permissions for individual data types.",
  "technicalDetails": "The root cause of this vulnerability lies in the implementation of the listAction method within the ResourceController of the CoreShop application. The controller fails to invoke the mandatory isGrantedOr403() security check before processing the request and returning the requested data to the user.\nIn the context of the Pimcore framework, which CoreShop extends, resource management controllers are expected to validate authorization tokens and permission sets against the requested resource type. By omitting the isGrantedOr403() call, the application effectively treats any authenticated session as having global read access to the resource listing endpoints.\nThe attack flow proceeds as follows: An authenticated user with restricted permissions identifies the URL structure for the resource list endpoints. Because the backend does not enforce server-side validation against these specific routes, the user can craft direct HTTP GET requests to these endpoints. The ResourceController executes the logic to retrieve records from the underlying persistence layer—such as payment providers, carriers, price rules, stores, and tax rules—and serializes them into the response body.\nThe lack of an authorization gate means that the server blindly honors these requests regardless of the user's role-based access control (RBAC) settings. An attacker can iterate through various endpoints to perform full enumeration of these resources, capturing sensitive metadata such as unique identifiers, names, and internal system identifiers.\nThis vulnerability specifically affects all versions of CoreShop up to and including 2026.2.2. The exploitation requires active authentication within the Pimcore backend, meaning the attack surface is limited to internal users or compromised accounts. However, the post-exploitation impact is significant as it leaks architectural and configuration details of the e-commerce backend. This information can be leveraged to map out the business logic and identify potential weaknesses in payment or pricing configurations, which could lead to further exploitation, such as price manipulation or the targeting of specific payment gateway integrations.\nThe failure demonstrates an oversight in the middleware or controller-level security architecture, where the implementation of administrative list views bypassed the centralized authorization service, leading to an insecure-by-default configuration for backend resources."
}
CVE-2026-108697: CoreShop Missing Authorization Vulnerability (MEDIUM Severity, CVSS: 4.3) | Sceawere