CVE-2026-32100: swag/platform-security: `/api/_info/config` route exposes information about licenses and active security fixes
Published Mar 12, 2026
·Updated
Shopware is an open commerce platform. /api/info/config route exposes information about active security fixes. This vulnerability is fixed in 2.0.16, 3.0.12, and 4.0.7.
Affected Software
2 affected components
Shopware Shopware
npm/swag/platform-security
Event History
Mar 12, 2026
CVE Published
via MITRE·06:10 PM
Data Sourced
via MITRE·06:10 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·06:16 PM
DescriptionSeverityWeakness
Nov 20, 58180
Event
via FIRST·09:08 AM
Frequently Asked Questions
1
What is the severity of CVE-2026-32100?
CVE-2026-32100 is classified as a security vulnerability that exposes sensitive configuration information.
2
How do I fix CVE-2026-32100?
To fix CVE-2026-32100, upgrade to Shopware versions 2.0.16, 3.0.12, or 4.0.7.
3
What information is exposed by CVE-2026-32100?
CVE-2026-32100 exposes information about licenses and active security fixes through the `/api/_info/config` route.
4
Which versions of Shopware are affected by CVE-2026-32100?
CVE-2026-32100 affects multiple versions of Shopware prior to the fixed versions 2.0.16, 3.0.12, and 4.0.7.
5
Is CVE-2026-32100 fixed in the latest Shopware release?
Yes, CVE-2026-32100 has been addressed in the latest releases of Shopware 2.0.16, 3.0.12, and 4.0.7.