CVE-2026-91154
Last modified
CVE-2026-91154 is a medium-severity vulnerability rated 6.9/10 on the CVSS scale. Missing Authentication for Critical Function (CWE-306) in the product cache revalidation Server Action (src/app/actions.ts, revalidateProducts) in MarcosCamara01 Ecommerce Template before commit ec97209 allows a remote, unauthenticated attacker to force expiration of the entire storefront product cache at will. The file declares "use server" at file scope, so every exported function compiles into a POST-invokable Server Action; revalidateProducts calls updateTag("products") with no session or role check, unlike the read-only actions in the same file which are safe by construction.
Description
Missing Authentication for Critical Function (CWE-306) in the product cache revalidation Server Action (src/app/actions.ts, revalidateProducts) in MarcosCamara01 Ecommerce Template before commit ec97209 allows a remote, unauthenticated attacker to force expiration of the entire storefront product cache at will. The file declares "use server" at file scope, so every exported function compiles into a POST-invokable Server Action; revalidateProducts calls updateTag("products") with no session or role check, unlike the read-only actions in the same file which are safe by construction. Two client components under src/components/admin import the function, which causes its Server Action id to be compiled into a public /_next/static chunk that the application's admin middleware (proxy.ts) does not gate, so any unauthenticated user can extract that id from the public bundle and invoke the action directly. With cacheComponents enabled, the entire storefront (home, categories, product pages, search) is served from "use cache" entries produced by getAllProducts, getCategoryProducts and getProduct, all tagged products with an hours-long cacheLife. Repeated unauthenticated invocation of revalidateProducts keeps that cache permanently cold, forcing every visitor's request to read the full product catalog from Postgres instead of serving from cache, degrading storefront availability at near-zero attacker cost.
Metrics
Weakness Enumeration
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| MarcosCamara01 | Ecommerce Template | < ec97209 |
References
Timeline
- Published
- Last Modified
- Status
- Received
Frequently Asked Questions
What is CVE-2026-91154?
How severe is CVE-2026-91154?
How do I fix CVE-2026-91154?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-91144ZFile through 5.0.5 fails to validate requested file paths a…7.5
- CVE-2026-91145Activiti through 7.1.0.M6 fails to validate hash-brace defer…7.1
- CVE-2026-91146Takahe through 0.11.0 fails to restrict URL schemes in link …6.1
- CVE-2026-91147A flaw was found in `cockpit-ws`. This vulnerability allows …5.9
- CVE-2026-91149A flaw was found in Cockpit. An unauthenticated remote attac…7.5
- CVE-2026-9115Insufficient policy enforcement in Service Worker in Google …4.3
- CVE-2026-9116Insufficient policy enforcement in ServiceWorker in Google C…4.3
- CVE-2026-91160OpenWA is a free, open source, self-hosted WhatsApp API gate…8.2
- CVE-2026-91161OpenWA is a free, open source, self-hosted WhatsApp API gate…6.4
- CVE-2026-91164Warpgate is an open source SSH, HTTPS and MySQL bastion host…4.3
- CVE-2026-91165Warpgate is an open source SSH, HTTPS and MySQL bastion host…2.4
- CVE-2026-91166Warpgate is an open source SSH, HTTPS and MySQL bastion host…5.7
Are you affected by CVE-2026-91154?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
