CVE-2026-53639
Sylius is an Open Source eCommerce Framework on Symfony. Starting in version 2.0.0 and prior to version 2.0.18, 2.1.15, and 2.2.6, the `GET /api/v2/shop/payment-requests/{hash}` and `PUT /api/v2/shop/payment-requests/{hash}` endpoints look up the payment request solely by the hash from the URL. No ownership check is performed against the authenticated customer or the underlying order. An attacker who obtains a payment request hash can read the payment request and, through the `payment` IRI in the response, recover the underlying order's `tokenValue` (which itself grants access to the full order, items, addresses, customer email, totals); and/or update the payment request payload (e.g. `target_path`, `after_path`). These fields are used by the front-end controller to redirect the user after the payment, so an attacker can flip them to an attacker-controlled URL and intercept the buyer. The hash is a UUID, so it has to be obtained out-of-band (logs, shared links, referrer headers, a co-located client), but once it is known no other credential is required, neither authentication nor knowledge of the order token. The creation endpoint `POST /api/v2/shop/orders/{tokenValue}/payment-requests` shares the same flaw: it resolves the target order solely from the `tokenValue` in the URL without verifying that the caller owns the order. The issue is fixed in versions 2.0.18, 2.1.15, and 2.2.6. As a workaround, add a query extension that filters the `GET` operation; decorate the `PUT` state provider, guard the `POST` creation endpoint with a command-bus middleware, and wire the services.
Scoring
- Severity
- MEDIUM
- CVSS base score
- 6.3
- CVSS vector
- CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N
- EPSS probability
- 0.54%
- CWE
- CWE-639
- Published
- 2026-09-08
- Last modified
- 2026-09-09
Affected products
- Sylius Sylius
- Sylius Sylius
- Sylius Sylius
Weakness type
Related vulnerabilities
- CVE-2026-47156 — MantisBT: SOAP API Authentication Bypass with Privilege Escalation to Administrator
- CVE-2026-67403 — Cash Collect contains an improper authorization vulnerability in the Sage AR Automation API....
- CVE-2026-86763 — snipe-it 7.0.12 through 8.6.3 Authorization Bypass via Importer
- CVE-2026-86761 — snipe-it 8.6.3 before 8.7.0 Authorization Bypass via print endpoints
- CVE-2026-86743 — Snipe-IT before 8.7.0 Authorization Bypass via Asset Acceptance Report
- CVE-2026-87809 — Siyuan before v3.8.2 Information Disclosure via Export Preview
- CVE-2026-87033 — Tanium addressed an improper access controls vulnerability in Comply.
- CVE-2026-87025 — Tanium addressed an improper access controls vulnerability in Comply.