Vulnerability in Sylius eCommerce Framework Exposes Payment Request Data
CVE-2026-53639

6.3MEDIUM

Key Information:

Vendor

Sylius

Status
Vendor
CVE Published:
8 September 2026

What is CVE-2026-53639?

The Sylius eCommerce Framework contains an access control vulnerability that affects specific API endpoints handling payment requests. The identified issue allows attackers to access payment request details without proper ownership verification. By exploiting this vulnerability, an unauthorized party can retrieve sensitive order information, including email addresses and totals, using a hash obtained through various means. Furthermore, attackers can manipulate the redirection paths in payment processes to redirect users to malicious sites. The flaw exists in certain versions and has been addressed in subsequent updates. To mitigate the risk, users are advised to apply the recommended patches or implement specific workarounds that enhance API endpoint protection.

Affected Version(s)

Sylius >= 2.0.0, < 2.0.18 < 2.0.0, 2.0.18

Sylius >= 2.1.0, < 2.1.15 < 2.1.0, 2.1.15

Sylius >= 2.2.0, < 2.2.6 < 2.2.0, 2.2.6

References

CVSS V4

Score:
6.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.