CVE-2026-100870
Received
Received - Intake
Password Reset Token Hijacking in Sylius
Vulnerability report for CVE-2026-100870, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.
Publication date: 2026-09-27
Last updated on: 2026-09-27
Assigner: VulnCheck
Description
Description
Sylius versions before 1.12.25, 1.13.17, 1.14.20, 2.1.16, and 2.2.9 build administrator password-reset links using the request Host header without validation, allowing unauthenticated attackers to redirect reset tokens to attacker-controlled domains. Attackers can request password resets for known administrator email addresses with forged Host headers to intercept valid reset tokens and take over administrator accounts.
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| sylius | sylius | From 1.12.0 (inc) to 1.12.25 (exc) |
| sylius | sylius | From 1.12.0 (inc) to 1.13.17 (exc) |
| sylius | sylius | From 1.12.0 (inc) to 1.14.20 (exc) |
| sylius | sylius | From 1.12.0 (inc) to 2.1.16 (exc) |
| sylius | sylius | From 1.12.0 (inc) to 2.2.9 (exc) |
| sylius | sylius | 1.12.25 |
| sylius | sylius | to 1.12.25 (exc) |
| sylius | sylius | 1.13.17 |
| sylius | sylius | 1.14.20 |
| sylius | sylius | 2.1.16 |
| sylius | sylius | 2.2.9 |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-640 | The product contains a mechanism for users to recover or change their passwords without knowing the original password, but the mechanism is weak. |