CVE-2026-53639
Last modified
CVE-2026-53639 is a medium-severity vulnerability rated 6.3/10 on the CVSS scale. Sylius is an Open Source eCommerce Framework on Symfony. Starting in version 2.0.0 and prior to version 2.0.18, 2.1.15, and 2.2.6, the `GET /api/v2/shop/payment-requests/{hash}` and `PUT /api/v2/shop/payment-requests/{hash}` endpoints look up the payment request solely by the hash from the URL. EPSS estimates a 0.54% chance of exploitation in the next 30 days.
Description
Sylius is an Open Source eCommerce Framework on Symfony. Starting in version 2.0.0 and prior to version 2.0.18, 2.1.15, and 2.2.6, the `GET /api/v2/shop/payment-requests/{hash}` and `PUT /api/v2/shop/payment-requests/{hash}` endpoints look up the payment request solely by the hash from the URL. No ownership check is performed against the authenticated customer or the underlying order. An attacker who obtains a payment request hash can read the payment request and, through the `payment` IRI in the response, recover the underlying order's `tokenValue` (which itself grants access to the full order, items, addresses, customer email, totals); and/or update the payment request payload (e.g. `target_path`, `after_path`). These fields are used by the front-end controller to redirect the user after the payment, so an attacker can flip them to an attacker-controlled URL and intercept the buyer. The hash is a UUID, so it has to be obtained out-of-band (logs, shared links, referrer headers, a co-located client), but once it is known no other credential is required, neither authentication nor knowledge of the order token. The creation endpoint `POST /api/v2/shop/orders/{tokenValue}/payment-requests` shares the same flaw: it resolves the target order solely from the `tokenValue` in the URL without verifying that the caller owns the order. The issue is fixed in versions 2.0.18, 2.1.15, and 2.2.6. As a workaround, add a query extension that filters the `GET` operation; decorate the `PUT` state provider, guard the `POST` creation endpoint with a command-bus middleware, and wire the services.
Metrics
Weakness Enumeration
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| Sylius | Sylius | >= 2.0.0, < 2.0.18; >= 2.1.0, < 2.1.15; >= 2.2.0, < 2.2.6 |
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2026-53639?
How severe is CVE-2026-53639?
How do I fix CVE-2026-53639?
How Strix Helps
- Uncovering a hidden BOLA in Appsmith's snapshot logicStrix autonomously discovered a BOLA/IDOR vulnerability in Appsmith's snapshot deletion path.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-53633Vitest is a testing framework powered by Vite. From 3.0.0 un…9.8
- CVE-2026-53634Sharp is a content management framework built for Laravel as…4.3
- CVE-2026-53635Open edX Platform enables the authoring and delivery of onli…7.6
- CVE-2026-53636Open edX Platform enables the authoring and delivery of onli…4.7
- CVE-2026-53637Sylius is an Open Source eCommerce Framework on Symfony. Ver…6.5
- CVE-2026-53638Sylius is an Open Source eCommerce Framework on Symfony. Sta…4.3
- CVE-2026-5364The Drag and Drop File Upload for Contact Form 7 plugin for …8.1
- CVE-2026-53640FOSSBilling is a free, open-source billing and client manage…2.3
- CVE-2026-53641FOSSBilling is a free, open-source billing and client manage…4.8
- CVE-2026-53642FOSSBilling is a free, open-source billing and client manage…5.3
- CVE-2026-53643FOSSBilling is a free, open-source billing and client manage…8.7
- CVE-2026-53644FOSSBilling is a free, open-source billing and client manage…8.6
Are you affected by CVE-2026-53639?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
