Impact
Sylius versions earlier than 1.12.25, 1.13.17, 1.14.20, 2.1.16, and 2.2.9 do not embed firewall identification in JSON Web Tokens issued by the separate Admin and Shop API endpoints. An attacker can exploit this gap by registering a shop customer account with an existing administrator's email address, receiving a JWT that the Admin API interprets as belonging to that administrator. This misidentification grants the attacker full administrative privileges, effectively bypassing authentication controls (CWE‑287).
Affected Systems
The affected product is Sylius, a commerce platform. Versions prior to 1.12.25, 1.13.17, 1.14.20, 2.1.16, and 2.2.9 are vulnerable; later releases incorporate the fix. Upgrade to any of those newer versions or apply the official patch to eliminate the vulnerability.
Risk and Exploitability
The CVSS score of 8.7 classifies this flaw as high severity. EPSS data is not available, so the exploitation probability cannot be quantified, but the attack can be achieved easily via the publicly exposed shop API. The vulnerability is not listed in the CISA KEV catalog, yet the ability to obtain unrestricted administrative access gives it high value to attackers. The likely attack vector is remote network access to the shop API, where an adversary crafts a registration request with an administrator's email and then uses the resulting token against the Admin API.
OpenCVE Enrichment