CVE-2026-53638
Deferred Deferred - Pending Action

Authorization Bypass in Sylius Shop Account API

Vulnerability report for CVE-2026-53638, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-08

Last updated on: 2026-09-14

Assigner: GitHub, Inc.

Description

Sylius is an Open Source eCommerce Framework on Symfony. Starting in version 2.0.0 and prior to version 2.0.18, 2.1.15, and 2.2.6, an authorization bypass vulnerability exists in the shop account API. The `PATCH /api/v2/shop/account/orders/{tokenValue}/payments/{paymentId}` endpoint, used by an authenticated shop customer to change the payment method of an order that has been placed but not yet paid (state `STATE_NEW`), does not validate that the chosen payment method is enabled for the order's channel. The equivalent checkout endpoint (`PATCH /api/v2/shop/orders/{tokenValue}/payments/{paymentId}`) correctly rejects out-of-channel payment methods with `HTTP 422`; the account endpoint silently accepts them and returns `HTTP 200`. An authenticated customer can therefore assign any globally enabled payment method to their own placed order, including methods that the store operator has explicitly excluded from that channel. The issue is fixed in versions: 2.0.18, 2.1.15, 2.2.6 and above. As a workaround, decorate the `Sylius\Bundle\ApiBundle\Changer\PaymentMethodChangerInterface` service in the application.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-08
Last Modified
2026-09-14
Generated
2026-09-29
AI Q&A
2026-09-10
EPSS Evaluated
2026-09-27
NVD

Affected Vendors & Products

Showing 3 associated CPEs
Vendor Product Version / Range
sylius sylius From 2.0.0 (inc) to 2.0.18 (exc)
sylius sylius 2.1.15
sylius sylius 2.2.6

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-863 The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is an authorization bypass in the Sylius eCommerce framework. It affects the shop account API where an authenticated customer can change the payment method of an unpaid order via the PATCH /api/v2/shop/account/orders/{tokenValue}/payments/{paymentId} endpoint. The issue is that the endpoint does not validate if the chosen payment method is enabled for the order's channel, allowing customers to assign any globally enabled payment method, even those excluded from that channel.

Impact Analysis

An attacker with a valid account could exploit this to assign a payment method to their order that the store operator has disabled for that channel. This could lead to unauthorized use of payment methods, potential financial loss, or bypassing channel-specific payment restrictions set by the store.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-53638. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart