CVE-2026-100871
EUVD-2026-8794327.09.2026, 13:16
Sylius versions before 1.12.25, 1.13.17, 1.14.20, 2.1.16, and 2.2.9 fail to include firewall identification in JWT tokens issued by separate Admin and Shop API endpoints. Attackers can register a shop customer account using an administrator's email address and obtain a token that the Admin API resolves to that administrator, granting full administrative access.Enginsight
Early Detection
Affected products identified ahead of NVD analysis through intelligence sources.
| Vendor | Product | Version | Source |
|---|---|---|---|
| sylius | sylius | 1.11.0 ≤ 𝑥 < 1.12.25 | CNA |
| sylius | sylius | 1.13.0 ≤ 𝑥 < 1.13.17 | CNA |
| sylius | sylius | 1.14.0 ≤ 𝑥 < 1.14.20 | CNA |
| sylius | sylius | 2.0.0 ≤ 𝑥 < 2.1.16 | CNA |
| sylius | sylius | 2.2.0 ≤ 𝑥 < 2.2.9 | CNA |
Common Weakness Enumeration
References