Skip to content

Weekly roundup

Open-source business platforms, week 35 2026: three critical Shopware advisories lead 31 fixes

Critical 9.6 Vendor: Open-source business platforms 31 advisories in scope Published

Open-source business platforms, week 35 of 2026: 31 in-scope flaws across Shopware, Dolibarr, Frappe, Drupal core and ERP. Three critical Shopware advisories and Dolibarr REST API issues stand out; no CISA KEV or exploited entries. Patch Shopware 6.6.10.23/6.7.13.1 and Dolibarr 24.0.0 first.

The release at a glance

Open-source business platforms released a combined set of 31 in-scope security advisories and CVEs for week 35 of 2026 (24–30 August). Of these, 3 are critical, 15 high, 11 medium and 2 low. Dolibarr accounts for 14, Shopware for 10, Frappe for 3, Drupal core for 3 and ERP for 1. None of the entries are listed in CISA's Known Exploited Vulnerabilities catalogue or reported as exploited. Shopware's fixes are consolidated in 6.6.10.23 for the 6.6 line and 6.7.13.1 for the 6.7 line. Dolibarr's release 24.0.0 carries the fixes for the Dolibarr issues.

What matters most

Shopware leads with three critical advisories. GHSA-6qhw-38wm-7g7h is a sandbox escape in App Scripts: a malicious or compromised installed App can execute arbitrary PHP and operating-system commands in the shop. GHSA-xj2c-8fw5-mr6m allows an unauthenticated attacker to poison the Host header in the administration password-reset flow, redirecting an administrator's reset link to an attacker-controlled domain and taking over the account if the administrator opens it. GHSA-xrcf-c96g-q5hr is stored SQL/DDL injection through custom-entity definitions supplied by an App, allowing arbitrary SQL with the database connection's permissions. Also prioritise GHSA-p37c-pm9p-7vm5, a pre-authentication SQL injection in the Store API that needs only a Sales Channel access key often exposed in headless Store API integrations, and GHSA-p67w-3mq7-rw2g, a path traversal through the media update endpoint that can lead to remote code execution with the media:update privilege. Each of these has a separate advisory page on this site.

Dolibarr's highest-risk issues centre on the email collector and REST APIs. CVE-2026-81730 is a path traversal through inbound email attachment filenames; a sender to a monitored mailbox can write content outside the attachment directory without holding a Dolibarr account. CVE-2026-71504 lets a user with member-creation rights reset any account password, including the system administrator. CVE-2026-81728 is SQL injection via CSV/XLSX import update keys for users with import permission. Several further 7.1–7.2 high Dolibarr REST API issues allow deleting payment records, overwriting portal passwords, altering company bank account details or modifying payroll fields. Dolibarr 24.0.0 fixes all of them.

Patch in this order

  1. Patch Shopware first. Apply 6.6.10.23 or 6.7.13.1, matching your installed line. Internet-facing shops using Store API or App Scripts carry the critical sandbox escape and password-reset poisoning. If you cannot patch immediately, enable Symfony trusted-host validation for GHSA-xj2c-8fw5-mr6m, restrict Store API exposure for GHSA-p37c-pm9p-7vm5, restrict the media:update privilege for GHSA-p67w-3mq7-rw2g, and install and update Apps only from trusted sources for GHSA-xrcf-c96g-q5hr.
  2. Patch Dolibarr to 24.0.0. Put internet-facing email collectors first because CVE-2026-81730 needs no Dolibarr account. Then close the REST API authorization and SQL injection issues, especially if non-administrative roles can create members, run imports or access third-party records.
  3. Work through the remaining Dolibarr, Frappe, Drupal core and ERP items in the table, starting with the other 7.1 high entries and then the medium and low ones. No CISA KEV due dates apply because this release has no KEV entries.

Beyond the patch

Open-source platform weeks like this are triage problems more than panic problems: the deciding questions are which Shopware or Dolibarr instance is reachable, which roles can touch the dangerous endpoints, and whether the latest hardening is actually in place. Our Implementation & Assessment Services can test the Shopware and Dolibarr deployments for the injection, authorisation and path-traversal gaps this release describes, while Virtual CISO Services (vCISO) can keep exposure management focused on internet-facing Store API, email collector and administration surfaces. Managed Detection & Response (MDR) can watch for the command execution and credential abuse that would follow an attempted exploit.

Every advisory in this release

IDProductSeverity
GHSA-6qhw-38wm-7g7hShopwareCritical 9.6Advisory →
GHSA-xj2c-8fw5-mr6mShopwareCritical 9.3Advisory →
GHSA-xrcf-c96g-q5hrShopwareCritical 9.1Advisory →
CVE-2026-81730dolibarrHigh 8.8Advisory →
CVE-2026-71504dolibarrHigh 8.6Advisory →
CVE-2026-81728dolibarrHigh 8.6Advisory →
GHSA-p37c-pm9p-7vm5ShopwareHigh 8.6Advisory →
GHSA-p67w-3mq7-rw2gShopwareHigh 8.0Advisory →
CVE-2026-71506dolibarrHigh 7.2Advisory →
CVE-2026-71505dolibarrHigh 7.1Advisory →
CVE-2026-71507dolibarrHigh 7.1Advisory →
CVE-2026-71508dolibarrHigh 7.1Advisory →
CVE-2026-71509dolibarrHigh 7.1Advisory →
CVE-2026-71510dolibarrHigh 7.1Advisory →
CVE-2026-71511dolibarrHigh 7.1Advisory →
CVE-2026-66003frappeHigh 7.1
CVE-2026-81729dolibarrHigh 7.1
CVE-2026-82634frappeHigh 7.1
GHSA-4wpv-5fvv-c3xpShopwareMedium 6.5Advisory →
GHSA-fgjq-45xv-rj8rShopwareMedium 6.3Advisory →
CVE-2026-55805Drupal coreMedium 5.4
CVE-2026-78160ERPMedium 5.3
CVE-2026-77923dolibarrMedium 5.3
CVE-2026-82633dolibarrMedium 5.3
GHSA-674c-5376-96rvShopwareMedium 5.3Advisory →
CVE-2026-71503dolibarrMedium 5.1
CVE-2026-81731frappeMedium 5.1
CVE-2026-15917Drupal coreMedium 4.7
CVE-2026-15916Drupal coreMedium 4.2
GHSA-f497-xgx3-22hqShopwareLow 3.7Advisory →
GHSA-rrc3-p9vx-5373ShopwareLow 3.1Advisory →

References

Sources: the CVE record (MITRE), NVD, CISA KEV and SSVC, ENISA EUVD, FIRST EPSS and the vendor's own advisory. Scores and dates are shown as those sources publish them. Entries marked GHSA have no CVE: their source is the security advisory the maintainers published in their official GitHub repository.

Written with AI assistance from the sources above and checked automatically against them before publication.