Junglewise Threat Intelligence

CVE-2026-100872: Sylius payment amount validation bypass in cart recalculation

CVE-2026-100872 · Severity: high · CVSS 7.5 · Published 2026-09-27

Technologies: Sylius. Vendors: Sylius.

Executive brief

Sylius is an open-source e-commerce platform used to power online stores and sales operations. The platform fails to properly validate order totals after a customer initiates a payment with a payment gateway, allowing an attacker to increase the order amount after the gateway has already captured payment for the original smaller amount. An attacker could exploit this to receive goods or services while paying significantly less, resulting in direct financial loss to the merchant.

Technical details

The vulnerability exists in Sylius's cart recalculation logic, which does not re-validate payment amounts during the post-gateway-capture phase. An unauthenticated attacker can modify an order total after initiating a transaction with the payment gateway, causing the system to mark an inflated order as fully paid even though the gateway only captured the original lower amount. This is a logic flaw in the payment reconciliation process with no authentication requirement.

Affected products

  • Sylius Sylius before 2.1.16 and before 2.2.9

Timeline

  • 2026-09-27: disclosed

References

Related threats