# CVE-2026-53639

## Summary

- **CVE ID:** CVE-2026-53639
- **Severity:** MEDIUM
- **CVSS Score:** 6.3 (CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N)
- **CWE:** CWE-639
- **Published:** Sep 8, 2026
- **Last Modified:** Sep 9, 2026

## Description

Sylius is an Open Source eCommerce Framework on Symfony. Starting in version 2.0.0 and prior to version 2.0.18, 2.1.15, and 2.2.6, the `GET /api/v2/shop/payment-requests/{hash}` and `PUT /api/v2/shop/payment-requests/{hash}` endpoints look up the payment request solely by the hash from the URL. No ownership check is performed against the authenticated customer or the underlying order. An attacker who obtains a payment request hash can read the payment request and, through the `payment` IRI in the response, recover the underlying order's `tokenValue` (which itself grants access to the full order, items, addresses, customer email, totals); and/or update the payment request payload (e.g. `target_path`, `after_path`). These fields are used by the front-end controller to redirect the user after the payment, so an attacker can flip them to an attacker-controlled URL and intercept the buyer. The hash is a UUID, so it has to be obtained out-of-band (logs, shared links, referrer headers, a co-located client), but once it is known no other credential is required, neither authentication nor knowledge of the order token. The creation endpoint `POST /api/v2/shop/orders/{tokenValue}/payment-requests` shares the same flaw: it resolves the target order solely from the `tokenValue` in the URL without verifying that the caller owns the order. The issue is fixed in versions 2.0.18, 2.1.15, and 2.2.6. As a workaround, add a query extension that filters the `GET` operation; decorate the `PUT` state provider, guard the `POST` creation endpoint with a command-bus middleware, and wire the services.

## Affected Products

- Sylius — Sylius (>= 2.0.0, < 2.0.18)
- Sylius — Sylius (>= 2.1.0, < 2.1.15)
- Sylius — Sylius (>= 2.2.0, < 2.2.6)

## References

- [CNA](https://github.com/Sylius/Sylius/security/advisories/GHSA-mr9r-h354-966r)

## Exploitation Prediction (EPSS)

- **EPSS Score:** 0.54%
- **EPSS Percentile:** 43.9

---
_Exported from OnDuty AI Vulnerability Intelligence on 2026-09-09._