JWT Audience Confusion in Sylius Affects Administrative Access
CVE-2026-100871

8.7HIGH

Key Information:

Vendor

Sylius

Status
Vendor
CVE Published:
27 September 2026

What is CVE-2026-100871?

A significant security flaw exists in the Sylius platform where selected versions fail to properly segregate firewall identification in the JSON Web Tokens (JWT) issued for Admin and Shop API endpoints. This oversight allows malicious users to create shop customer accounts using an administrator's email address. By doing so, they can obtain a JWT that the Admin API treats as valid for the administrator account, thereby granting them unauthorized and full administrative access. To mitigate this issue, upgrades to at least versions 1.12.25, 1.13.17, 1.14.20, 2.1.16, or 2.2.9 are strongly advised.

Affected Version(s)

Sylius 1.11.0 < 1.12.25

Sylius 1.13.0 < 1.13.17

Sylius 1.14.0 < 1.14.20

References

CVSS V4

Score:
8.7
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.