PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-108697 CoreShop CVE debrief

A missing authorization vulnerability in CoreShop through version 2026.2.2 allows low-privileged backend users to list permission-restricted resources. This issue arises from the ResourceController listAction skipping the isGrantedOr403() check, enabling authenticated Pimcore users without resource permissions to enumerate payment providers, carriers, price rules, stores, and tax rules, including their ids, names, and identifiers.

Vendor
CoreShop
Product
Unknown
CVSS
MEDIUM 5.3
CISA KEV
Not listed in stored evidence
Original CVE published
2026-10-11
Original CVE updated
2026-10-11
Advisory published
2026-10-11
Advisory updated
2026-10-11

Who should care

Defenders responsible for CoreShop deployments, particularly those with low-privileged backend users, should assess their exposure to this vulnerability. They should verify the presence of this issue in their inventory and implement necessary controls to prevent unauthorized access to resources.

Why it matters

CVE-2026-108697 is a missing authorization vulnerability in CoreShop through version 2026.2.2 that allows low-privileged users to enumerate restricted resources. Defenders should verify the presence of this vulnerability, assess exposure, and implement controls to prevent unauthorized access.

  • Defenders need to verify the presence of this vulnerability in their CoreShop deployments to prevent unauthorized resource enumeration.
  • Low-privileged backend users may be able to list restricted resources, potentially leading to information disclosure.
  • Implementing compensating controls, such as restricting access to the ResourceController listAction, is necessary to prevent exploitation.
  • Monitoring for unauthorized access attempts and implementing additional logging can help detect potential exploitation.

Technical summary

The vulnerability is caused by the ResourceController listAction in CoreShop through version 2026.2.2 not properly checking for authorization. This allows low-privileged backend users to list permission-restricted resources, including payment providers, carriers, price rules, stores, and tax rules. The issue arises from the lack of isGrantedOr403() check, enabling authenticated Pimcore users without resource permissions to enumerate these resources. Defenders should verify the presence of this vulnerability in their inventory and assess the exposure of their systems, particularly those with low-privileged backend users.

Defensive priority

Defenders should prioritize verifying the presence of this vulnerability in their inventory and assess the exposure of their systems, particularly those with low-privileged backend users. They should also monitor for any unauthorized access to resources and implement compensating controls if necessary.

Recommended defensive actions

  • Verify the presence of CoreShop version 2026.2.2 or earlier in your inventory.
  • Assess the exposure of your systems, particularly those with low-privileged backend users.
  • Monitor for unauthorized access to resources and implement compensating controls if necessary.
  • Restrict access to the ResourceController listAction for low-privileged users.
  • Implement additional logging and monitoring to detect potential exploitation attempts.

Evidence notes

The vulnerability is confirmed in CoreShop through version 2026.2.2. The issue is related to the ResourceController listAction not performing the required authorization check. Authenticated users lacking permissions can exploit this to list restricted resources.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-108697 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-108697

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-108697 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-108697

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • CoreShop through 2026.2.2 Missing Authorization via ResourceController listAction

    Unverified legacy reference

    URL: https://raw.githubusercontent.com/CVEProject/cvelistV5/main/cves/2026/108xxx/CVE-2026-108697.json

    cve_program_cvelist_v5

  • Source reference

    Unverified legacy reference

    URL: https://hackmd.io/TsX1brUNT8G2iQGO9YlCkQ

    Supplemental source - third-party-advisory

  • Source reference

    Unverified legacy reference

    URL: https://github.com/coreshop/CoreShop/blob/2026.2.2/src/CoreShop/Bundle/ResourceBundle/Controller/ResourceController.php

    Supplemental source - technical-description

  • Source reference

    Unverified legacy reference

    URL: https://github.com/coreshop/CoreShop/blob/2026.2.2/src/CoreShop/Bundle/PayumPaymentBundle/Controller/PaymentProviderController.php

    Supplemental source - technical-description

  • Source reference

    Unverified legacy reference

    URL: https://github.com/coreshop/CoreShop

    Supplemental source - product

  • Source reference

    Unverified legacy reference

    URL: https://www.vulncheck.com/advisories/coreshop-through-2026.2.2-missing-authorization-via-resourcecontroller-listaction

    Supplemental source - third-party-advisory

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.