Authentication Bypass by Spoofing in Sylius - #VU146814

 

Authentication Bypass by Spoofing in Sylius - #VU146814

Published: September 2, 2026


Vulnerability identifier: #VU146814
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: N/A
CWE-ID: CWE-290
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to gain administrative access to the API.

The vulnerability exists due to authentication bypass by spoofing in JWT authentication across the admin and shop API firewalls when processing JWTs issued for a different firewall. A remote user can register a shop customer account with an administrator\'s e-mail address and present the resulting token to the Admin API to gain administrative access to the API.

Exploitation is possible when the API is enabled, shop registration is available, and an administrator e-mail address can be learned or guessed.


Affected software

Sylius

Remediation

Install security update from vendor's website.

Sylius - addressed in versions 1.12.25, 1.13.17, 1.14.20, 2.1.16, 2.2.9

External References

Related Security Bulletins