Junglewise Threat Intelligence

CVE-2026-53638: Sylius is an Open Source eCommerce Framework on Symfony. Starting in version 2.0.0 and prior to version 2.0.18, 2.1.15, and 2.2.6, an author

CVE-2026-53638 · Severity: medium · CVSS 4.3 · Published 2026-09-08

Technologies: Sylius. Vendors: Sylius.

Executive brief

Sylius is an open-source e-commerce platform. A vulnerability in its shop account API allows logged-in customers to bypass payment method restrictions. Specifically, a customer could change their order's payment method to one that the store owner has disabled for that specific sales channel, potentially allowing the use of unauthorized or unintended payment options.

Technical details

An authorization bypass vulnerability exists in the Sylius shop account API due to missing validation in the `PATCH /api/v2/shop/account/orders/{tokenValue}/payments/{paymentId}` endpoint. While the standard checkout endpoint correctly validates payment methods against the order's channel, the account endpoint fails to perform this check for orders in the `STATE_NEW` status. An authenticated attacker can exploit this by sending a PATCH request to assign any globally enabled payment method to their order, even if that method is explicitly restricted from the order's channel. This issue is rooted in the `PaymentMethodChanger` implementation and is fixed in versions 2.0.18, 2.1.15, and 2.2.6.

Affected products

  • Sylius Sylius/Sylius >= 2.0.0, < 2.0.18; >= 2.1.0, < 2.1.15; >= 2.2.0, < 2.2.6

Timeline

  • 2026-06-02: disclosed
  • 2026-07-09: advisory
  • 2026-07-09: patched

References

Related threats