CoreShop through 2026.2.2 contains a missing authorization vulnerability that allows low-privileged backend users to list permission-restricted resources because ResourceController listAction skips the isGrantedOr403() check. Authenticated Pimcore users lacking resource permissions can request the generated list routes to enumerate payment providers, carriers, price rules, stores, and tax rules including ids, names, and identifiers.
Advisories

No advisories yet.

Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Sun, 11 Oct 2026 13:45:00 +0000

Type Values Removed Values Added
Description CoreShop through 2026.2.2 contains a missing authorization vulnerability that allows low-privileged backend users to list permission-restricted resources because ResourceController listAction skips the isGrantedOr403() check. Authenticated Pimcore users lacking resource permissions can request the generated list routes to enumerate payment providers, carriers, price rules, stores, and tax rules including ids, names, and identifiers.
Title CoreShop through 2026.2.2 Missing Authorization via ResourceController listAction
First Time appeared Coreshop
Coreshop coreshop
Weaknesses CWE-862
CPEs cpe:2.3:a:coreshop:coreshop:*:*:*:*:*:*:*:*
Vendors & Products Coreshop
Coreshop coreshop
References
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N'}

cvssV4_0

{'score': 5.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-10-11T13:25:58.117Z

Reserved: 2026-10-10T23:08:35.775Z

Link: CVE-2026-108697

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-11T14:17:03.973

Modified: 2026-10-11T14:17:03.973

Link: CVE-2026-108697

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-11T15:15:09Z

Weaknesses