CVE-2026-91154
Received Received - Intake

Authentication Bypass in MarcosCamara01 Ecommerce Template

Vulnerability report for CVE-2026-91154, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-28

Last updated on: 2026-09-28

Assigner: Secur0

Description

Missing Authentication for Critical Function (CWE-306) in the product cache revalidation Server Action (src/app/actions.ts, revalidateProducts) in MarcosCamara01 Ecommerce Template before commit ec97209 allows a remote, unauthenticated attacker to force expiration of the entire storefront product cache at will. The file declares "use server" at file scope, so every exported function compiles into a POST-invokable Server Action; revalidateProducts calls updateTag("products") with no session or role check, unlike the read-only actions in the same file which are safe by construction. Two client components under src/components/admin import the function, which causes its Server Action id to be compiled into a public /_next/static chunk that the application's admin middleware (proxy.ts) does not gate, so any unauthenticated user can extract that id from the public bundle and invoke the action directly. With cacheComponents enabled, the entire storefront (home, categories, product pages, search) is served from "use cache" entries produced by getAllProducts, getCategoryProducts and getProduct, all tagged products with an hours-long cacheLife. Repeated unauthenticated invocation of revalidateProducts keeps that cache permanently cold, forcing every visitor's request to read the full product catalog from Postgres instead of serving from cache, degrading storefront availability at near-zero attacker cost.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-28
Last Modified
2026-09-28
Generated
2026-09-28
AI Q&A
2026-09-28
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
marcoscamara01 ecommerce_template *

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-306 The product does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This is a Missing Authentication for Critical Function (CWE-306) vulnerability in the MarcosCamara01 Ecommerce Template. The issue is in the product cache revalidation Server Action (revalidateProducts) in src/app/actions.ts. The function allows unauthenticated attackers to force expiration of the entire storefront product cache by invoking it directly. The file uses 'use server' at scope, making all exported functions POST-invokable without session or role checks. Attackers can extract the Server Action ID from public chunks and trigger cache invalidation, degrading performance by forcing full catalog recomputation from Postgres on every request.

Detection Guidance

Check for unauthorized POST requests to the /_next/static chunk containing the revalidateProducts Server Action ID. Monitor for repeated cache invalidation attempts or unusual traffic patterns targeting the product cache.

Impact Analysis

This vulnerability allows unauthenticated attackers to repeatedly invalidate the product cache, forcing the storefront to serve uncached content. This degrades performance and availability by making every visitor's request read the full product catalog from Postgres instead of serving cached responses. The attack imposes minimal cost on the attacker while significantly impacting legitimate users and storefront operations.

Compliance Impact

This vulnerability could impact compliance with GDPR and HIPAA by enabling unauthorized access to cached product data, potentially exposing personal or sensitive information. Unauthenticated cache revalidation may violate data protection requirements for access controls and integrity of cached data.

Mitigation Strategies

Upgrade to a version of the Ecommerce Template that includes commit ec97209 or later. This update moves the revalidateProducts function to a server-only module and adds internal credential checks to prevent unauthorized access.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-91154. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart