Description
Sylius through 2.3.0 contains an authorization bypass vulnerability that allows unauthenticated attackers to read unmoderated and rejected product reviews because the AcceptedExtension filter is not applied to the item operation. Attackers can enumerate sequential ids on GET /api/v2/shop/product-reviews/{id} to retrieve review titles, ratings, comments, timestamps and author first names, bypassing merchant moderation.
Published: 2026-10-11
Score: 6.9 Medium
EPSS: n/a
KEV: No
Impact: Unauthorized disclosure of product reviews
Action: Apply patch
AI Analysis

Impact

Sylius versions through 2.3.0 contain an authorization bypass that allows attackers without authentication to read unmoderated and rejected product reviews. The filter that should enforce moderation, the AcceptedExtension, is not applied to the item operation, enabling an attacker to retrieve review titles, ratings, comments, timestamps and author first names. This results in the disclosure of potentially sensitive customer feedback and merchant information. The weakness is categorized as CWE‑639, indicating that user‑controlled conditions are exploited to bypass normal authorization checks.

Affected Systems

The affected vendor and product are Sylius, specifically the Sylius e‑commerce platform. All releases up to and including version 2.3.0 are vulnerable. No specific sub‑components beyond the Shop API Product‑Review endpoint are listed, but the vulnerability resides in the default configuration of the API bundle of Sylius.

Risk and Exploitability

The CVSS score of 6.9 reflects a medium severity vulnerability. Although the EPSS score is not available, the lack of an authentication requirement and the ability to enumerate sequential identifiers on the publicly exposed endpoint suggest that exploitation is feasible over the network. The vulnerability is currently not listed in the CISA KEV catalog, indicating that there is no known mass exploitation campaign. Nonetheless, any attacker who discovers product-review identifiers can obtain a range of data, making a moderate risk assessment appropriate for e‑commerce sites that rely on the default operational settings.

Generated by OpenCVE AI on October 11, 2026 at 13:46 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade Sylius to a version that includes the authorization fix, such as the release following 2.3.0.
  • If an immediate upgrade is not possible, reconfigure the /api/v2/shop/product-reviews endpoint to require authentication or to restrict it to users with appropriate merchant roles.
  • Alternatively, disable or override the AcceptedExtension filter for the item operation so that unmoderated reviews cannot be retrieved by unauthenticated clients.

Generated by OpenCVE AI on October 11, 2026 at 13:46 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 11 Oct 2026 12:45:00 +0000

Type Values Removed Values Added
Description Sylius through 2.3.0 contains an authorization bypass vulnerability that allows unauthenticated attackers to read unmoderated and rejected product reviews because the AcceptedExtension filter is not applied to the item operation. Attackers can enumerate sequential ids on GET /api/v2/shop/product-reviews/{id} to retrieve review titles, ratings, comments, timestamps and author first names, bypassing merchant moderation.
Title Sylius through 2.3.0 Authorization Bypass via Shop API Product-Review Endpoint
First Time appeared Sylius
Sylius sylius
Weaknesses CWE-639
CPEs cpe:2.3:a:sylius:sylius:*:*:*:*:*:*:*:*
Vendors & Products Sylius
Sylius sylius
References
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N'}

cvssV4_0

{'score': 6.9, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-10-11T12:19:33.967Z

Reserved: 2026-10-11T01:52:33.372Z

Link: CVE-2026-108724

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-11T13:17:16.000

Modified: 2026-10-11T13:17:16.000

Link: CVE-2026-108724

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-11T14:00:18Z

Weaknesses
  • CWE-639

    Authorization Bypass Through User-Controlled Key