Improper Enforcement of Behavioral Workflow in Sylius - #VU146813

 

Improper Enforcement of Behavioral Workflow in Sylius - #VU146813

Published: September 2, 2026


Vulnerability identifier: #VU146813
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N]
CVE-ID: N/A
CWE-ID: CWE-841
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to manipulate payment status and mark an order as fully paid for an inflated total.

The vulnerability exists due to improper enforcement of behavioral workflow in OrderPaymentProcessor and OrderPaymentsRemover when recalculating an order after a gateway transaction has started. A remote attacker can pay a smaller legitimate amount and then enlarge the same order to manipulate payment status and mark an order as fully paid for an inflated total.

The issue occurs because the captured amount is not verified against the order\'s current total when the gateway later reports the transaction as successful.


Affected software

Sylius

Remediation

Install security update from vendor's website.

Sylius - addressed in versions 2.1.16, 2.2.9

External References

Related Security Bulletins