CVE-2026-91154: Missing authentication in Ecommerce Template product cache revalidation allows unauthenticated denial of service

Published Sep 28, 2026
·
Updated

Missing Authentication for Critical Function (CWE-306) in the product cache revalidation Server Action (src/app/actions.ts, revalidateProducts) in MarcosCamara01 Ecommerce Template before commit ec97209 allows a remote, unauthenticated attacker to force expiration of the entire storefront product cache at will. The file declares "use server" at file scope, so every exported function compiles into a POST-invokable Server Action; revalidateProducts calls updateTag("products") with no session or role check, unlike the read-only actions in the same file which are safe by construction. Two client components under src/components/admin import the function, which causes its Server Action id to be compiled into a public /next/static chunk that the application's admin middleware (proxy.ts) does not gate, so any unauthenticated user can extract that id from the public bundle and invoke the action directly. With cacheComponents enabled, the entire storefront (home, categories, product pages, search) is served from "use cache" entries produced by getAllProducts, getCategoryProducts and getProduct, all tagged products with an hours-long cacheLife. Repeated unauthenticated invocation of revalidateProducts keeps that cache permanently cold, forcing every visitor's request to read the full product catalog from Postgres instead of serving from cache, degrading storefront availability at near-zero attacker cost.

Affected Software

1 affected component
MarcosCamara01 Ecommerce Template

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade MarcosCamara01 Ecommerce Template to a version that resolves this vulnerability.

    Patch ec97209

Event History

Sep 28, 2026
CVE Published
via MITRE·03:29 PM
Data Sourced
via MITRE·03:29 PM
RemedyDescriptionWeakness
Data Sourced
via NVD·04:17 PM
DescriptionSeverityWeakness

Frequently Asked Questions

1

Which deployments are exposed?

Deployments based on versions before commit ec97209 are affected when the product cache revalidation Server Action is present. The described storefront-wide cache impact applies with cacheComponents enabled, where product-related pages use entries tagged "products".

2

What does an attacker need to exploit this?

No authentication, session, or administrative access is required. An attacker can obtain the Server Action identifier from a public /_next/static client bundle and invoke the POST-capable action directly.

3

What is the operational impact of repeated requests?

Each invocation expires the shared "products" cache tag, affecting cached home, category, product, and search content. Repeated requests can prevent effective cache reuse and force repeated product-data regeneration, causing denial of service through increased backend load.

4

How can I determine whether an instance has the vulnerable behavior?

Check whether the deployment predates commit ec97209 and whether src/app/actions.ts exports revalidateProducts under a file-level "use server" directive without a session or role check. Also confirm that its Server Action identifier is exposed in public client chunks and that the admin middleware does not gate access to those chunks.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203