Junglewise Threat Intelligence

CVE-2026-100871: Sylius JWT token firewall identification bypass

CVE-2026-100871 · Severity: high · CVSS 8.8 · Published 2026-09-27

Technologies: Sylius. Vendors: Sylius.

Executive brief

Sylius is an open-source eCommerce platform that manages both customer storefronts and administrative functions through separate APIs. A flaw in how JWT authentication tokens are issued allows an attacker to register a customer account with an administrator's email address, obtain a token, and use it to gain full administrative access to the platform. This enables complete takeover of the eCommerce business and access to sensitive data.

Technical details

The vulnerability stems from JWT tokens issued by the Admin and Shop API endpoints failing to include firewall identification, allowing tokens to be resolved interchangeably across both endpoints. An attacker can register a shop customer using an administrator's email, receive a Shop API token, and present it to the Admin API endpoint where it resolves to the administrator account. This is an authentication bypass requiring only network access and the ability to create a customer account.

Affected products

  • Sylius Sylius before 1.12.25, 1.13.17, 1.14.20, 2.1.16, 2.2.9

Timeline

  • 2026-09-27: disclosed: CVE-2026-100871 published

References

Related threats