CVE-2026-108724 PUBLISHED

Sylius through 2.3.0 Authorization Bypass via Shop API Product-Review Endpoint

Assigner: VulnCheck
Reserved: 11.10.2026 Published: 11.10.2026 Updated: 11.10.2026

Sylius through 2.3.0 contains an authorization bypass vulnerability that allows unauthenticated attackers to read unmoderated and rejected product reviews because the AcceptedExtension filter is not applied to the item operation. Attackers can enumerate sequential ids on GET /api/v2/shop/product-reviews/{id} to retrieve review titles, ratings, comments, timestamps and author first names, bypassing merchant moderation.

Metrics

CVSS Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N
CVSS Score: 6.9

Product Status

Vendor Sylius
Product Sylius
Versions Default: unaffected
  • affected from 0 to 2.3.0 (incl.)

Credits

  • HaiND from the Post and Telecommunication Institute of Technology finder

References

Problem Types

  • Authorization Bypass Through User-Controlled Key CWE