Shopware Password Reset Vulnerability Leading to Session Retention

Vulnerability

A vulnerability exists in Shopware versions through 6.1.0, where user sessions remain active after a password is reset via the password recovery process. This issue has been addressed in version 6.4.8.1. For users on older versions 6.1, 6.2, and 6.3, a plugin is available to implement the necessary security measures.

Impact

This vulnerability allows for user sessions to remain active even after a password reset, which could lead to unauthorized access if the session is hijacked.

Remediation

Users are advised to update to Shopware version 6.4.8.2, available through the Auto-Updater or the Shopware download overview. For versions 6.1, 6.2, and 6.3, a plugin is available to address this vulnerability.

Added: May 15, 2026, 8:49 AM
Updated: May 15, 2026, 8:49 AM

Vulnerability Rating

Custom Algorithm
spread
6.4
impact
1.3
exploitability
6.0
remediation
7.7
relevance
0.0
threat
0.0
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.