Payment Amount Vulnerability in Sylius by Sylius
CVE-2026-100872
8.7HIGH
What is CVE-2026-100872?
In certain versions of Sylius, there is a vulnerability that allows unauthenticated attackers to exploit the payment process by modifying order totals post-transaction initiation. This occurs due to improper validation of payment amounts during cart recalculation. Attackers can exploit this flaw by initially capturing a small payment and subsequently inflating the order amount. The system may misleadingly mark the inflated order as fully paid, leading to potential financial losses for merchants.
Affected Version(s)
Sylius 2.0.0 < 2.1.16
Sylius 2.2.0 < 2.2.9
