CVE-2026-100869

Source
https://cve.org/CVERecord?id=CVE-2026-100869
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-100869.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-100869
Aliases
  • GHSA-2rv4-pjmm-7fxf
Published
2026-09-27T13:09:54Z
Modified
2026-09-28T03:48:31Z
Severity
  • 8.2 (High) CVSS_V4 - CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N CVSS Calculator
Summary
Sylius 2.x before 2.1.16 and 2.2.9 Arbitrary Payment Action via Shop API
Details

Sylius versions before 2.1.16 and 2.2.9 fail to restrict payment request actions in the Shop API endpoint, allowing customers to trigger refunds on completed orders. Attackers with order tokens can submit arbitrary payment actions like refunds that payment gateways execute while Sylius maintains order as paid, causing financial loss.

Database specific
{
    "cna_assigner":  "VulnCheck",
    "cwe_ids":  [
        "CWE-863"
    ],
    "osv_generated_from":  "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/100xxx/CVE-2026-100869.json"
}
References

Affected packages

Git / github.com/sylius/sylius

Affected ranges

Type
GIT
Repo
https://github.com/sylius/sylius
Events
Database specific
Show details
{
    "extracted_events":  [
        {
            "introduced":  "2.0.0"
        },
        {
            "fixed":  "2.1.16"
        },
        {
            "introduced":  "2.2.0"
        },
        {
            "fixed":  "2.2.9"
        }
    ],
    "source":  "AFFECTED_FIELD"
}

Affected versions

v2.*
v2.0.0
v2.0.1
v2.0.2
v2.0.3
v2.1.0
v2.1.1
v2.1.10
v2.1.11
v2.1.12
v2.1.13
v2.1.14
v2.1.15
v2.1.2
v2.1.3
v2.1.4
v2.1.5
v2.1.6
v2.1.7
v2.1.8
v2.1.9
v2.2.0
v2.2.1
v2.2.2
v2.2.3
v2.2.4
v2.2.5
v2.2.6
v2.2.7
v2.2.8

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-100869.json"