Missing Authentication Vulnerability in MarcosCamara01 Ecommerce Template
CVE-2026-91154

6.9MEDIUM

Key Information:

Vendor
CVE Published:
28 September 2026

What is CVE-2026-91154?

A vulnerability exists in the MarcosCamara01 Ecommerce Template related to missing authentication for critical functions. This issue arises from the 'revalidateProducts' action, which allows remote, unauthenticated attackers to force expiration of the storefront product cache without proper session or role validation. By exploiting this flaw, attackers can degrade the availability of the storefront, leading to performance issues and server strain as every request prompts a full catalog read from the database instead of utilizing cached data. Additionally, this vulnerability enables unauthorized access to invoke server actions that should be restricted, posing significant risks to the integrity and functionality of the ecommerce platform.

Affected Version(s)

Ecommerce Template 0

References

CVSS V4

Score:
6.9
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Robert Mihaila
Amirreza Fadaeizadeh Bidari
Dario Rivas Quero
Secur0 CNA
.