CVE-2026-100869: Sylius 2.x before 2.1.16 and 2.2.9 Arbitrary Payment Action via Shop API

Published Sep 27, 2026
·
Updated

Sylius versions before 2.1.16 and 2.2.9 fail to restrict payment request actions in the Shop API endpoint, allowing customers to trigger refunds on completed orders. Attackers with order tokens can submit arbitrary payment actions like refunds that payment gateways execute while Sylius maintains order as paid, causing financial loss.

Affected Software

1 affected component
Sylius Sylius<2.1.16, <2.2.9

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade Sylius to a version that resolves this vulnerability.

    Fixed in 2.1.16
  2. Upgrade

    Upgrade Sylius to a version that resolves this vulnerability.

    Fixed in 2.2.9

Event History

Sep 27, 2026
CVE Published
via MITRE·01:09 PM
Data Sourced
via MITRE·01:09 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·01:16 PM
DescriptionSeverityWeakness

Frequently Asked Questions

1

Who can exploit this issue?

An attacker needs an order token for a completed order. No authenticated account or user interaction is required according to the supplied vector.

2

Are all Sylius deployments affected by default?

The issue affects Sylius 2.x versions before 2.1.16 and 2.2.9 where the Shop API payment request endpoint does not restrict payment actions. Exposure depends on the Shop API endpoint being reachable and an attacker obtaining an order token.

3

What is the practical impact of exploitation?

An attacker can submit a refund action for a completed order, and the payment gateway may execute it while Sylius continues to record the order as paid. This can produce direct financial loss and inconsistent payment records.

4

How can teams check whether they may already be affected?

Review completed orders for refunds executed by the payment gateway where the corresponding Sylius order remains marked paid. Also review Shop API payment-action requests for refund operations associated with exposed or unexpected order tokens.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203