Weekly roundup
Open-source business platforms, week 35 2026: three critical Shopware advisories lead 31 fixes
Open-source business platforms, week 35 of 2026: 31 in-scope flaws across Shopware, Dolibarr, Frappe, Drupal core and ERP. Three critical Shopware advisories and Dolibarr REST API issues stand out; no CISA KEV or exploited entries. Patch Shopware 6.6.10.23/6.7.13.1 and Dolibarr 24.0.0 first.
The release at a glance
Open-source business platforms released a combined set of 31 in-scope security advisories and CVEs for week 35 of 2026 (24–30 August). Of these, 3 are critical, 15 high, 11 medium and 2 low. Dolibarr accounts for 14, Shopware for 10, Frappe for 3, Drupal core for 3 and ERP for 1. None of the entries are listed in CISA's Known Exploited Vulnerabilities catalogue or reported as exploited. Shopware's fixes are consolidated in 6.6.10.23 for the 6.6 line and 6.7.13.1 for the 6.7 line. Dolibarr's release 24.0.0 carries the fixes for the Dolibarr issues.
What matters most
Shopware leads with three critical advisories. GHSA-6qhw-38wm-7g7h is a sandbox escape in App Scripts: a malicious or compromised installed App can execute arbitrary PHP and operating-system commands in the shop. GHSA-xj2c-8fw5-mr6m allows an unauthenticated attacker to poison the Host header in the administration password-reset flow, redirecting an administrator's reset link to an attacker-controlled domain and taking over the account if the administrator opens it. GHSA-xrcf-c96g-q5hr is stored SQL/DDL injection through custom-entity definitions supplied by an App, allowing arbitrary SQL with the database connection's permissions. Also prioritise GHSA-p37c-pm9p-7vm5, a pre-authentication SQL injection in the Store API that needs only a Sales Channel access key often exposed in headless Store API integrations, and GHSA-p67w-3mq7-rw2g, a path traversal through the media update endpoint that can lead to remote code execution with the media:update privilege. Each of these has a separate advisory page on this site.
Dolibarr's highest-risk issues centre on the email collector and REST APIs. CVE-2026-81730 is a path traversal through inbound email attachment filenames; a sender to a monitored mailbox can write content outside the attachment directory without holding a Dolibarr account. CVE-2026-71504 lets a user with member-creation rights reset any account password, including the system administrator. CVE-2026-81728 is SQL injection via CSV/XLSX import update keys for users with import permission. Several further 7.1–7.2 high Dolibarr REST API issues allow deleting payment records, overwriting portal passwords, altering company bank account details or modifying payroll fields. Dolibarr 24.0.0 fixes all of them.
Patch in this order
- Patch Shopware first. Apply 6.6.10.23 or 6.7.13.1, matching your installed line. Internet-facing shops using Store API or App Scripts carry the critical sandbox escape and password-reset poisoning. If you cannot patch immediately, enable Symfony trusted-host validation for GHSA-xj2c-8fw5-mr6m, restrict Store API exposure for GHSA-p37c-pm9p-7vm5, restrict the
media:updateprivilege for GHSA-p67w-3mq7-rw2g, and install and update Apps only from trusted sources for GHSA-xrcf-c96g-q5hr. - Patch Dolibarr to 24.0.0. Put internet-facing email collectors first because CVE-2026-81730 needs no Dolibarr account. Then close the REST API authorization and SQL injection issues, especially if non-administrative roles can create members, run imports or access third-party records.
- Work through the remaining Dolibarr, Frappe, Drupal core and ERP items in the table, starting with the other 7.1 high entries and then the medium and low ones. No CISA KEV due dates apply because this release has no KEV entries.
Beyond the patch
Open-source platform weeks like this are triage problems more than panic problems: the deciding questions are which Shopware or Dolibarr instance is reachable, which roles can touch the dangerous endpoints, and whether the latest hardening is actually in place. Our Implementation & Assessment Services can test the Shopware and Dolibarr deployments for the injection, authorisation and path-traversal gaps this release describes, while Virtual CISO Services (vCISO) can keep exposure management focused on internet-facing Store API, email collector and administration surfaces. Managed Detection & Response (MDR) can watch for the command execution and credential abuse that would follow an attempted exploit.
Every advisory in this release
| ID | Product | Severity | |
|---|---|---|---|
| GHSA-6qhw-38wm-7g7h | Shopware | Critical 9.6 | Advisory → |
| GHSA-xj2c-8fw5-mr6m | Shopware | Critical 9.3 | Advisory → |
| GHSA-xrcf-c96g-q5hr | Shopware | Critical 9.1 | Advisory → |
| CVE-2026-81730 | dolibarr | High 8.8 | Advisory → |
| CVE-2026-71504 | dolibarr | High 8.6 | Advisory → |
| CVE-2026-81728 | dolibarr | High 8.6 | Advisory → |
| GHSA-p37c-pm9p-7vm5 | Shopware | High 8.6 | Advisory → |
| GHSA-p67w-3mq7-rw2g | Shopware | High 8.0 | Advisory → |
| CVE-2026-71506 | dolibarr | High 7.2 | Advisory → |
| CVE-2026-71505 | dolibarr | High 7.1 | Advisory → |
| CVE-2026-71507 | dolibarr | High 7.1 | Advisory → |
| CVE-2026-71508 | dolibarr | High 7.1 | Advisory → |
| CVE-2026-71509 | dolibarr | High 7.1 | Advisory → |
| CVE-2026-71510 | dolibarr | High 7.1 | Advisory → |
| CVE-2026-71511 | dolibarr | High 7.1 | Advisory → |
| CVE-2026-66003 | frappe | High 7.1 | |
| CVE-2026-81729 | dolibarr | High 7.1 | |
| CVE-2026-82634 | frappe | High 7.1 | |
| GHSA-4wpv-5fvv-c3xp | Shopware | Medium 6.5 | Advisory → |
| GHSA-fgjq-45xv-rj8r | Shopware | Medium 6.3 | Advisory → |
| CVE-2026-55805 | Drupal core | Medium 5.4 | |
| CVE-2026-78160 | ERP | Medium 5.3 | |
| CVE-2026-77923 | dolibarr | Medium 5.3 | |
| CVE-2026-82633 | dolibarr | Medium 5.3 | |
| GHSA-674c-5376-96rv | Shopware | Medium 5.3 | Advisory → |
| CVE-2026-71503 | dolibarr | Medium 5.1 | |
| CVE-2026-81731 | frappe | Medium 5.1 | |
| CVE-2026-15917 | Drupal core | Medium 4.7 | |
| CVE-2026-15916 | Drupal core | Medium 4.2 | |
| GHSA-f497-xgx3-22hq | Shopware | Low 3.7 | Advisory → |
| GHSA-rrc3-p9vx-5373 | Shopware | Low 3.1 | Advisory → |
References
Vendor advisory
- App Script sandbox escape allows arbitrary PHP and OS command execution
- Admin account takeover via Host-header password-reset poisoning
- Stored SQL/DDL Injection via Custom Entity Field Names (App Manifest)
- Dolibarr fix (GitHub)
- Dolibarr fix (GitHub)
- Dolibarr fix (GitHub)
- Pre-authentication SQL injection in Store API
- Path traversal via writable media.fileExtension leads to remote code execution (single …
Patch and release notes
- github.com/Dolibarr/dolibarr/blob/23.0.4/htdocs/emailcollector/lib/emailcollector.lib.p…
- VulnCheck Advisory: Dolibarr 9.0.0 through 23.0.4 Path Traversal via EmailCollector Att…
- Patch Commit
- VulnCheck Advisory: Dolibarr before 24.0.0 SQL Injection via the CSV and XLSX Import Up…
- Patch Commit
- Patch Commit
- Patch Commit
- Patch Commit
Exploit and analysis
Other
- github.com/Dolibarr/dolibarr
- www.vulncheck.com/advisories/dolibarr-members-rest-api-improper-authorization-via-passw…
- github.com/Dolibarr/dolibarr/blob/23.0.4/htdocs/core/modules/import/import_csv.modules.…
- www.vulncheck.com/advisories/dolibarr-payments-rest-api-improper-authorization-via-dele…
- www.vulncheck.com/advisories/dolibarr-rest-api-broken-object-level-authorization-via-th…
- www.vulncheck.com/advisories/dolibarr-rest-api-broken-object-level-authorization-via-ba…
- www.vulncheck.com/advisories/dolibarr-rest-api-improper-authorization-via-user-update-e…
CVE / GHSA
- GHSA-6qhw-38wm-7g7h — GitHub
- GHSA-xj2c-8fw5-mr6m — GitHub
- GHSA-xrcf-c96g-q5hr — GitHub
- CVE-2026-81730 — cve.org
- CVE-2026-81730 — NVD
- EUVD-2026-67235 — ENISA EUVD
- CVE-2026-71504 — cve.org
- CVE-2026-71504 — NVD
- EUVD-2026-65076 — ENISA EUVD
- CVE-2026-81728 — cve.org
- CVE-2026-81728 — NVD
- EUVD-2026-67233 — ENISA EUVD
- GHSA-p37c-pm9p-7vm5 — GitHub
- GHSA-p67w-3mq7-rw2g — GitHub
- CVE-2026-71506 — cve.org
- CVE-2026-71506 — NVD
- EUVD-2026-65079 — ENISA EUVD
- CVE-2026-71505 — cve.org
- CVE-2026-71505 — NVD
- EUVD-2026-65078 — ENISA EUVD
- CVE-2026-71507 — cve.org
- CVE-2026-71507 — NVD
- EUVD-2026-65080 — ENISA EUVD
- CVE-2026-71508 — cve.org
- CVE-2026-71508 — NVD
- EUVD-2026-65081 — ENISA EUVD