CVE-2026-32142: shopware/commercial: `/api/_info/config` route exposes information about licenses
Published Mar 12, 2026
·Updated
Shopware is an open commerce platform. /api/info/config route exposes information about licenses. This vulnerability is fixed in 7.8.1 and 6.10.15.
Affected Software
3 affected components
Shopware Shopware<7.8.1
Shopware Shopware<6.10.15
shopware/commercial
Event History
Mar 12, 2026
CVE Published
via MITRE·06:17 PM
Data Sourced
via MITRE·06:17 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·07:16 PM
DescriptionSeverityWeakness
Nov 20, 58180
Event
via FIRST·10:23 AM
Frequently Asked Questions
1
What is the severity of CVE-2026-32142?
CVE-2026-32142 is a critical vulnerability that exposes sensitive license information through the '/api/_info/config' route in Shopware.
2
How do I fix CVE-2026-32142?
To fix CVE-2026-32142, upgrade your Shopware installation to version 7.8.1 or 6.10.15.
3
What are the affected versions for CVE-2026-32142?
CVE-2026-32142 affects versions of Shopware prior to 7.8.1 and 6.10.15.
4
What type of information is exposed due to CVE-2026-32142?
CVE-2026-32142 exposes sensitive information about licenses that could potentially be exploited.
5
Is CVE-2026-32142 an active vulnerability?
Yes, CVE-2026-32142 is considered active and poses a risk to users of vulnerable versions of Shopware.