CVE-2026-100869: Sylius 2.x before 2.1.16 and 2.2.9 Arbitrary Payment Action via Shop API
Sylius versions before 2.1.16 and 2.2.9 fail to restrict payment request actions in the Shop API endpoint, allowing customers to trigger refunds on completed orders. Attackers with order tokens can submit arbitrary payment actions like refunds that payment gateways execute while Sylius maintains order as paid, causing financial loss.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Syliusto a version that resolves this vulnerability.Fixed in 2.1.16 - Upgrade
Upgrade
Syliusto a version that resolves this vulnerability.Fixed in 2.2.9
Event History
Frequently Asked Questions
Who can exploit this issue?
An attacker needs an order token for a completed order. No authenticated account or user interaction is required according to the supplied vector.
Are all Sylius deployments affected by default?
The issue affects Sylius 2.x versions before 2.1.16 and 2.2.9 where the Shop API payment request endpoint does not restrict payment actions. Exposure depends on the Shop API endpoint being reachable and an attacker obtaining an order token.
What is the practical impact of exploitation?
An attacker can submit a refund action for a completed order, and the payment gateway may execute it while Sylius continues to record the order as paid. This can produce direct financial loss and inconsistent payment records.
How can teams check whether they may already be affected?
Review completed orders for refunds executed by the payment gateway where the corresponding Sylius order remains marked paid. Also review Shop API payment-action requests for refund operations associated with exposed or unexpected order tokens.