Missing Authentication Vulnerability in MarcosCamara01 Ecommerce Template
CVE-2026-91154
What is CVE-2026-91154?
A vulnerability exists in the MarcosCamara01 Ecommerce Template related to missing authentication for critical functions. This issue arises from the 'revalidateProducts' action, which allows remote, unauthenticated attackers to force expiration of the storefront product cache without proper session or role validation. By exploiting this flaw, attackers can degrade the availability of the storefront, leading to performance issues and server strain as every request prompts a full catalog read from the database instead of utilizing cached data. Additionally, this vulnerability enables unauthorized access to invoke server actions that should be restricted, posing significant risks to the integrity and functionality of the ecommerce platform.
Affected Version(s)
Ecommerce Template 0
References
CVSS V4
Timeline
Vulnerability published
Vulnerability Reserved
