Junglewise Threat Intelligence

CVE-2026-53639: Sylius is an Open Source eCommerce Framework on Symfony. Starting in version 2.0.0 and prior to version 2.0.18, 2.1.15, and 2.2.6, the `GET

CVE-2026-53639 · Severity: medium · CVSS 4 · Published 2026-09-08

Technologies: Sylius. Vendors: Sylius.

Executive brief

Sylius, an e-commerce platform, contains a security flaw in its payment request system. An attacker who obtains a specific payment link can view sensitive customer order details (including email and addresses) or redirect future payments to a malicious website. This could lead to the theft of customer data or financial fraud by intercepting buyer payments.

Technical details

An Insecure Direct Object Reference (IDOR) exists in the GET, PUT, and POST endpoints for payment requests in Sylius. The application fails to verify if the authenticated user or guest session owns the order associated with a payment request hash or token. By obtaining a payment request UUID, an attacker can retrieve the underlying order's tokenValue, granting access to full order details including customer PII. Additionally, attackers can modify 'target_path' and 'after_path' fields to redirect users to malicious URLs during the payment flow. The issue is fixed in versions 2.0.18, 2.1.15, and 2.2.6.

Affected products

  • Sylius Sylius/Sylius >= 2.0.0, < 2.0.18
  • Sylius Sylius/Sylius >= 2.1.0, < 2.1.15
  • Sylius Sylius/Sylius >= 2.2.0, < 2.2.6

Timeline

  • 2026-06-02: disclosed: Initial publication date
  • 2026-07-09: advisory: Last updated date

References

Related threats