PatchSiren cyber security CVE debrief
CVE-2026-108697 CoreShop CVE debrief
A missing authorization vulnerability in CoreShop through version 2026.2.2 allows low-privileged backend users to list permission-restricted resources. This issue arises from the ResourceController listAction skipping the isGrantedOr403() check, enabling authenticated Pimcore users without resource permissions to enumerate payment providers, carriers, price rules, stores, and tax rules, including their ids, names, and identifiers.
- Vendor
- CoreShop
- Product
- Unknown
- CVSS
- MEDIUM 5.3
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-10-11
- Original CVE updated
- 2026-10-11
- Advisory published
- 2026-10-11
- Advisory updated
- 2026-10-11
Who should care
Defenders responsible for CoreShop deployments, particularly those with low-privileged backend users, should assess their exposure to this vulnerability. They should verify the presence of this issue in their inventory and implement necessary controls to prevent unauthorized access to resources.
Why it matters
CVE-2026-108697 is a missing authorization vulnerability in CoreShop through version 2026.2.2 that allows low-privileged users to enumerate restricted resources. Defenders should verify the presence of this vulnerability, assess exposure, and implement controls to prevent unauthorized access.
- Defenders need to verify the presence of this vulnerability in their CoreShop deployments to prevent unauthorized resource enumeration.
- Low-privileged backend users may be able to list restricted resources, potentially leading to information disclosure.
- Implementing compensating controls, such as restricting access to the ResourceController listAction, is necessary to prevent exploitation.
- Monitoring for unauthorized access attempts and implementing additional logging can help detect potential exploitation.
Technical summary
The vulnerability is caused by the ResourceController listAction in CoreShop through version 2026.2.2 not properly checking for authorization. This allows low-privileged backend users to list permission-restricted resources, including payment providers, carriers, price rules, stores, and tax rules. The issue arises from the lack of isGrantedOr403() check, enabling authenticated Pimcore users without resource permissions to enumerate these resources. Defenders should verify the presence of this vulnerability in their inventory and assess the exposure of their systems, particularly those with low-privileged backend users.
Defensive priority
Defenders should prioritize verifying the presence of this vulnerability in their inventory and assess the exposure of their systems, particularly those with low-privileged backend users. They should also monitor for any unauthorized access to resources and implement compensating controls if necessary.
Recommended defensive actions
- Verify the presence of CoreShop version 2026.2.2 or earlier in your inventory.
- Assess the exposure of your systems, particularly those with low-privileged backend users.
- Monitor for unauthorized access to resources and implement compensating controls if necessary.
- Restrict access to the ResourceController listAction for low-privileged users.
- Implement additional logging and monitoring to detect potential exploitation attempts.
Evidence notes
The vulnerability is confirmed in CoreShop through version 2026.2.2. The issue is related to the ResourceController listAction not performing the required authorization check. Authenticated users lacking permissions can exploit this to list restricted resources.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-108697 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-108697
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-108697 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-108697
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
CoreShop through 2026.2.2 Missing Authorization via ResourceController listAction
Unverified legacy reference
URL: https://raw.githubusercontent.com/CVEProject/cvelistV5/main/cves/2026/108xxx/CVE-2026-108697.json
cve_program_cvelist_v5
-
Source reference
Unverified legacy reference
URL: https://hackmd.io/TsX1brUNT8G2iQGO9YlCkQ
Supplemental source - third-party-advisory
-
Source reference
Unverified legacy reference
URL: https://github.com/coreshop/CoreShop/blob/2026.2.2/src/CoreShop/Bundle/ResourceBundle/Controller/ResourceController.php
Supplemental source - technical-description
-
Source reference
Unverified legacy reference
URL: https://github.com/coreshop/CoreShop/blob/2026.2.2/src/CoreShop/Bundle/PayumPaymentBundle/Controller/PaymentProviderController.php
Supplemental source - technical-description
-
Source reference
Unverified legacy reference
URL: https://github.com/coreshop/CoreShop
Supplemental source - product
-
Source reference
Unverified legacy reference
URL: https://www.vulncheck.com/advisories/coreshop-through-2026.2.2-missing-authorization-via-resourcecontroller-listaction
Supplemental source - third-party-advisory
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.