CVE-2026-100871

Source
https://cve.org/CVERecord?id=CVE-2026-100871
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-100871.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-100871
Aliases
  • GHSA-f6mx-qxjc-55xf
Published
2026-09-27T13:09:55Z
Modified
2026-09-29T03:46:05Z
Severity
  • 8.7 (High) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N CVSS Calculator
Summary
Sylius before 1.12.25, 1.13.17, 1.14.20, 2.1.16, and 2.2.9 JWT Audience Confusion Allows Admin API Authentication
Details

Sylius versions before 1.12.25, 1.13.17, 1.14.20, 2.1.16, and 2.2.9 fail to include firewall identification in JWT tokens issued by separate Admin and Shop API endpoints. Attackers can register a shop customer account using an administrator's email address and obtain a token that the Admin API resolves to that administrator, granting full administrative access.

Database specific
{
    "cna_assigner":  "VulnCheck",
    "cwe_ids":  [
        "CWE-287"
    ],
    "osv_generated_from":  "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/100xxx/CVE-2026-100871.json"
}
References

Affected packages

Git / github.com/sylius/sylius

Affected ranges

Type
GIT
Repo
https://github.com/sylius/sylius
Events
Database specific
Show details
{
    "extracted_events":  [
        {
            "introduced":  "1.11.0"
        },
        {
            "fixed":  "1.12.25"
        },
        {
            "introduced":  "1.13.0"
        },
        {
            "fixed":  "1.13.17"
        },
        {
            "introduced":  "1.14.0"
        },
        {
            "fixed":  "1.14.20"
        },
        {
            "introduced":  "2.0.0"
        },
        {
            "fixed":  "2.1.16"
        },
        {
            "introduced":  "2.2.0"
        },
        {
            "fixed":  "2.2.9"
        }
    ],
    "source":  "AFFECTED_FIELD"
}

Affected versions

v1.*
v1.13.0
v1.13.1
v1.13.10
v1.13.11
v1.13.12
v1.13.13
v1.13.14
v1.13.15
v1.13.16
v1.13.2
v1.13.3
v1.13.4
v1.13.5
v1.13.6
v1.13.7
v1.13.8
v1.13.9
v1.14.0
v1.14.1
v1.14.10
v1.14.11
v1.14.12
v1.14.13
v1.14.14
v1.14.15
v1.14.16
v1.14.17
v1.14.18
v1.14.19
v1.14.2
v1.14.3
v1.14.4
v1.14.5
v1.14.6
v1.14.7
v1.14.8
v1.14.9
v2.*
v2.0.0
v2.0.1
v2.0.2
v2.0.3
v2.1.0
v2.1.1
v2.1.10
v2.1.11
v2.1.12
v2.1.13
v2.1.14
v2.1.15
v2.1.2
v2.1.3
v2.1.4
v2.1.5
v2.1.6
v2.1.7
v2.1.8
v2.1.9
v2.2.0
v2.2.1
v2.2.2
v2.2.3
v2.2.4
v2.2.5
v2.2.6
v2.2.7
v2.2.8

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-100871.json"