CVE-2026-100869 PUBLISHED

Sylius 2.x before 2.1.16 and 2.2.9 Arbitrary Payment Action via Shop API

Assigner: VulnCheck
Reserved: 27.09.2026 Published: 27.09.2026 Updated: 27.09.2026

Sylius versions before 2.1.16 and 2.2.9 fail to restrict payment request actions in the Shop API endpoint, allowing customers to trigger refunds on completed orders. Attackers with order tokens can submit arbitrary payment actions like refunds that payment gateways execute while Sylius maintains order as paid, causing financial loss.

Metrics

CVSS Vector: CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N
CVSS Score: 8.2

Product Status

Vendor Sylius
Product Sylius
Versions Default: unaffected
  • affected from 2.0.0 to 2.1.16 (excl.)
  • affected from 2.2.0 to 2.2.9 (excl.)

Credits

  • Alfonsas Cirtautas finder
  • leediay153 finder

References

Problem Types

  • Incorrect Authorization CWE