Sceawere
Vulnerability Detail
CVE-2026-100872UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
Sylius Payment Amount Validation Bypass
Vulnerability Metadata
- Severity
- High
- Score / CVSS
- 7.5
- Creation Date
- 19h ago
- Vendor
- Sylius
- Product
- Sylius
- Attack Type
- Insufficient Verification of Data Authenticity
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
- Attack Complexity
- LOW
Narrative and Response
Description
Sylius versions before 2.1.16 and 2.2.9 fail to validate payment amounts during cart recalculation, allowing unauthenticated attackers to modify order totals after gateway transaction initiation. Attackers can pay a small amount, enlarge the order after gateway capture, and have the system mark the inflated order as fully paid while the gateway captured only the original amount.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "7.5",
"pubDate": "2026-09-27T13:16:38.523Z",
"pubdate": "2026-09-27T13:16:38.523Z",
"executiveSummary": "This vulnerability is an improper input validation flaw affecting the Sylius e-commerce framework that allows for payment authorization bypass. The issue resides in the cart recalculation logic during the payment gateway process.\nBy manipulating the order totals after a transaction has been initiated but before final confirmation, unauthenticated attackers can effectively underpay for goods and services.\nSuccessful exploitation results in the system marking orders as fully paid despite the payment gateway receiving only a fraction of the intended amount. This exposes merchants to significant financial loss and inventory discrepancies.\nThe vulnerability affects Sylius versions prior to 2.1.16 and 2.2.9. The risk is critical, as it requires no prior authentication and can be executed by any user interacting with the checkout process.",
"technicalDetails": "The root cause of this vulnerability is the lack of strict server-side validation regarding order total consistency during the post-initiation phase of the payment lifecycle. In the affected versions of Sylius, the system fails to verify that the final order amount matches the amount authorized by the external payment gateway once the cart is modified.\nThe exploitation flow begins when an attacker initiates a checkout process for a high-value item or collection of items. After the payment gateway session is created and the initial authorization or capture request is triggered, the attacker manipulates the cart state. Because the application logic does not re-validate the order total against the previously authorized payment amount during the final order confirmation, the application incorrectly assumes the updated, higher cart total has been satisfied by the original transaction.\nThis behavior is essentially a race condition or a logic flaw where the backend assumes that the transaction status provided by the gateway covers the current state of the order, even if the order was modified in the interim. Since there is no binding mechanism between the specific order total and the transaction ID generated by the payment provider, the system is susceptible to state mismatch.\nAffected components include the cart management services and payment processing modules within the core framework. The vulnerability is network-exposed and does not require elevated privileges or authentication, as it occurs during the standard public-facing checkout flow.\nPost-exploitation impact involves the order management system triggering an 'order paid' status for orders where the captured funds are significantly lower than the final cart total. This allows attackers to acquire goods at a fraction of their cost or inject higher value items into a transaction after the payment has already been authorized for a lesser amount, circumventing financial controls entirely."
}