Executive brief
Sylius is an open-source e-commerce platform. A vulnerability in its shop account API allows logged-in customers to bypass payment method restrictions. Specifically, a customer could change their order's payment method to one that the store owner has disabled for that specific sales channel, potentially allowing the use of unauthorized or unintended payment options.
Technical details
An authorization bypass vulnerability exists in the Sylius shop account API due to missing validation in the `PATCH /api/v2/shop/account/orders/{tokenValue}/payments/{paymentId}` endpoint. While the standard checkout endpoint correctly validates payment methods against the order's channel, the account endpoint fails to perform this check for orders in the `STATE_NEW` status. An authenticated attacker can exploit this by sending a PATCH request to assign any globally enabled payment method to their order, even if that method is explicitly restricted from the order's channel. This issue is rooted in the `PaymentMethodChanger` implementation and is fixed in versions 2.0.18, 2.1.15, and 2.2.6.
Affected products
- Sylius Sylius/Sylius >= 2.0.0, < 2.0.18; >= 2.1.0, < 2.1.15; >= 2.2.0, < 2.2.6
Timeline
- 2026-06-02: disclosed
- 2026-07-09: advisory
- 2026-07-09: patched