Vulnerabilities
Report: CVE-2026-31888 - Shopware has user enumeration via distinct error codes on Store API login endpoint
CVE ID :CVE-2026-31888 Published : March 11, 2026, 6:53 p.m. | 32 minutes ago Description :Shopware is an open commerce platform. Prior to 6.7.8.1 and 6.6.10.15, the Store API login endpoint (POST /store-api/account/login) returns different error codes depending on whether the submitted email address belongs to a registered customer (CHECKOUT__CUSTOMER_AUTH_BAD_CREDENTIALS) or is unknown (CHECKOUT__CUSTOMER_NOT_FOUND). The
CVE Details
CVE ID
Published
March 11, 2026