CVE-2026-100871

EUVD-2026-87943
Sylius versions before 1.12.25, 1.13.17, 1.14.20, 2.1.16, and 2.2.9 fail to include firewall identification in JWT tokens issued by separate Admin and Shop API endpoints. Attackers can register a shop customer account using an administrator's email address and obtain a token that the Admin API resolves to that administrator, granting full administrative access.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
VulnCheckCNA
8.8 HIGH
NETWORK
LOW
LOW
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: Unknown
Early Detection
Affected products identified ahead of NVD analysis through intelligence sources.
VendorProductVersionSource
syliussylius
1.11.0 ≤
𝑥
< 1.12.25
CNA
syliussylius
1.13.0 ≤
𝑥
< 1.13.17
CNA
syliussylius
1.14.0 ≤
𝑥
< 1.14.20
CNA
syliussylius
2.0.0 ≤
𝑥
< 2.1.16
CNA
syliussylius
2.2.0 ≤
𝑥
< 2.2.9
CNA