Authentication Bypass by Spoofing in Sylius - #VU146814
Published: September 2, 2026
Vulnerability details
The vulnerability allows a remote user to gain administrative access to the API.
The vulnerability exists due to authentication bypass by spoofing in JWT authentication across the admin and shop API firewalls when processing JWTs issued for a different firewall. A remote user can register a shop customer account with an administrator\'s e-mail address and present the resulting token to the Admin API to gain administrative access to the API.
Exploitation is possible when the API is enabled, shop registration is available, and an administrator e-mail address can be learned or guessed.