CVE-2026-53639
Deferred Deferred - Pending Action

Authentication Bypass in Sylius Payment Requests

Vulnerability report for CVE-2026-53639, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-08

Last updated on: 2026-09-09

Assigner: GitHub, Inc.

Description

Sylius is an Open Source eCommerce Framework on Symfony. Starting in version 2.0.0 and prior to version 2.0.18, 2.1.15, and 2.2.6, the `GET /api/v2/shop/payment-requests/{hash}` and `PUT /api/v2/shop/payment-requests/{hash}` endpoints look up the payment request solely by the hash from the URL. No ownership check is performed against the authenticated customer or the underlying order. An attacker who obtains a payment request hash can read the payment request and, through the `payment` IRI in the response, recover the underlying order's `tokenValue` (which itself grants access to the full order, items, addresses, customer email, totals); and/or update the payment request payload (e.g. `target_path`, `after_path`). These fields are used by the front-end controller to redirect the user after the payment, so an attacker can flip them to an attacker-controlled URL and intercept the buyer. The hash is a UUID, so it has to be obtained out-of-band (logs, shared links, referrer headers, a co-located client), but once it is known no other credential is required, neither authentication nor knowledge of the order token. The creation endpoint `POST /api/v2/shop/orders/{tokenValue}/payment-requests` shares the same flaw: it resolves the target order solely from the `tokenValue` in the URL without verifying that the caller owns the order. The issue is fixed in versions 2.0.18, 2.1.15, and 2.2.6. As a workaround, add a query extension that filters the `GET` operation; decorate the `PUT` state provider, guard the `POST` creation endpoint with a command-bus middleware, and wire the services.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-08
Last Modified
2026-09-09
Generated
2026-09-29
AI Q&A
2026-09-09
EPSS Evaluated
2026-09-27
NVD

Affected Vendors & Products

Showing 3 associated CPEs
Vendor Product Version / Range
sylius sylius From 2.0.0 (inc) to 2.0.18 (exc)
sylius sylius 2.1.15
sylius sylius 2.2.6

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-639 The system's authorization functionality does not prevent one user from gaining access to another user's data or record by modifying the key value identifying the data.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability in Sylius, an eCommerce framework, allows attackers to access or modify payment requests and related order details without proper authentication. The issue occurs because the system only checks the payment request hash in the URL without verifying ownership or requiring additional credentials. An attacker who obtains a valid hash can read sensitive payment and order information or redirect users to malicious URLs.

Detection Guidance

This vulnerability involves missing ownership checks in Sylius payment request endpoints. To detect it, inspect API logs for unauthorized access attempts to GET /api/v2/shop/payment-requests/{hash}, PUT /api/v2/shop/payment-requests/{hash}, or POST /api/v2/shop/orders/{tokenValue}/payment-requests. Look for requests with mismatched customer/order ownership or unusual tokenValue/hash usage.

Impact Analysis

If exploited, this vulnerability could lead to unauthorized access to payment requests, order details, customer emails, addresses, and totals. Attackers could also modify payment request fields to redirect users to attacker-controlled URLs, potentially intercepting sensitive data or transactions. The hash required for exploitation may be obtained from logs, shared links, or referrer headers.

Compliance Impact

This vulnerability could violate GDPR by exposing personal data such as customer emails and addresses without consent. For HIPAA, it may risk unauthorized access to protected health information if order details include such data. Compliance failures could result in legal penalties, reputational damage, and loss of trust due to unauthorized data exposure.

Mitigation Strategies

Upgrade Sylius to versions 2.0.18, 2.1.15, or 2.2.6 or later. As a temporary workaround, add a query extension to filter GET operations, decorate the PUT state provider, guard the POST creation endpoint with a command-bus middleware, and ensure proper service wiring.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-53639. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart