Sceawere
Vulnerability Detail
CVE-2026-100869UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
Sylius Shop API Payment Bypass
Vulnerability Metadata
- Severity
- Medium
- Score / CVSS
- 5.9
- Creation Date
- 19h ago
- Vendor
- Sylius
- Product
- Sylius
- Attack Type
- Incorrect Authorization
- Vector String
- CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N
- Attack Complexity
- HIGH
Narrative and Response
Description
Sylius versions before 2.1.16 and 2.2.9 fail to restrict payment request actions in the Shop API endpoint, allowing customers to trigger refunds on completed orders. Attackers with order tokens can submit arbitrary payment actions like refunds that payment gateways execute while Sylius maintains order as paid, causing financial loss.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "5.9",
"pubDate": "2026-09-27T13:16:38.100Z",
"pubdate": "2026-09-27T13:16:38.100Z",
"executiveSummary": "This vulnerability is an improper access control issue within the Sylius Shop API that allows unauthorized state transitions for payment resources. Affected versions include all releases prior to 2.1.16 and 2.2.9.\nThe flaw stems from a lack of validation regarding payment request actions initiated via the API. Attackers possessing a valid order token can invoke administrative or system-level payment actions, specifically triggering refunds on orders that have already reached a 'paid' status.\nThe primary impact is unauthorized financial manipulation. By forcing a payment gateway to process a refund request, an attacker can effectively reverse a transaction while the Sylius internal state continues to track the order as successfully paid. This results in direct financial loss for the merchant and a significant integrity violation within the e-commerce transaction workflow.\nExploitation requires knowledge of a valid order token, which may be obtainable through intercepted traffic or exposed order history. No additional authentication or elevated administrative privileges are required, as the API endpoint incorrectly assumes that the possession of an order token implies legitimate authorization to perform any associated payment action.",
"technicalDetails": "The root cause of this vulnerability lies in an inadequate authorization layer within the Sylius Shop API’s payment processing logic. The API fails to enforce mandatory access control checks when processing incoming payment action requests, specifically neglecting to verify whether the requester has the authority to trigger destructive operations such as refunds.\nIn the vulnerable versions, the API endpoint responsible for payment interaction does not differentiate between standard status updates and sensitive state-changing operations. When a request is sent to the Shop API with a valid order token, the system processes the payload without validating the user's privilege level or the legitimacy of the requested payment action context.\nThe attack flow begins with the acquisition of an order token corresponding to a completed order. The attacker transmits a crafted API request to the payment endpoint, specifying a refund action within the request payload. Because the underlying controller or service fails to gate this action against the current state of the order or the identity of the requester, the application forwards the instruction to the integrated payment gateway.\nUpon receiving the request, the payment gateway—acting on behalf of the application—processes the refund. Consequently, the funds are returned to the attacker's payment method. Critically, the Sylius platform does not synchronize this external state change back to the internal order status, leaving the system in a state where the order record falsely reflects a completed payment despite the funds having been returned. This discrepancy facilitates financial fraud and obscures the audit trail.\nThis vulnerability is classified as an authorization bypass. The lack of proper restrictive logic within the payment controller allows for 'Insecure Direct Object Reference' (IDOR) style exploitation, where the order token serves as the sole identifier, and the API incorrectly permits any state-transition command associated with that token to execute.\nAffected systems are those running Sylius versions < 2.1.16 and < 2.2.9. Exposure is limited to the public-facing Shop API, meaning any actor with network access to the API endpoints can potentially attempt this exploitation if they possess a valid order token."
}