Description
Sylius is an Open Source eCommerce Framework on Symfony. Starting in version 2.0.0 and prior to version 2.0.18, 2.1.15, and 2.2.6, an authorization bypass vulnerability exists in the shop account API. The `PATCH /api/v2/shop/account/orders/{tokenValue}/payments/{paymentId}` endpoint, used by an authenticated shop customer to change the payment method of an order that has been placed but not yet paid (state `STATE_NEW`), does not validate that the chosen payment method is enabled for the order's channel. The equivalent checkout endpoint (`PATCH /api/v2/shop/orders/{tokenValue}/payments/{paymentId}`) correctly rejects out-of-channel payment methods with `HTTP 422`; the account endpoint silently accepts them and returns `HTTP 200`. An authenticated customer can therefore assign any globally enabled payment method to their own placed order, including methods that the store operator has explicitly excluded from that channel. The issue is fixed in versions: 2.0.18, 2.1.15, 2.2.6 and above. As a workaround, decorate the `Sylius\Bundle\ApiBundle\Changer\PaymentMethodChangerInterface` service in the application.
Published: 2026-09-08
Score: 4.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Authorization bypass allowing alteration of payment method
Action: Apply Patch
AI Analysis

Impact

The vulnerability in the shop account API endpoint does not check whether a payment method chosen by a customer belongs to the channel associated with the order. An authenticated user, having placed an order that is still in the "STATE_NEW" status, can therefore assign any globally enabled payment method, even those excluded from that channel by the store operator. This allows the customer to override channel‑specific payment restrictions, potentially leading to fraudulent transaction processing or violating business rules.

Affected Systems

Sylius eCommerce Framework (Sylius) versions starting with 2.0.0 and earlier than 2.0.18, 2.1.15, and 2.2.6 are affected. The issue is fixed in those specified release thresholds and subsequently.

Risk and Exploitability

With a CVSS score of 4.3 the vulnerability is considered low‑to‑moderate severity. The EPSS score is not available and it is not listed in the CISA KEV catalog. Exploitation requires an authenticated customer account and an order that has not yet been paid; the attack does not grant code execution or elevated privileges beyond those of the user, but it does provide a mechanism to bypass operator‑defined payment method constraints.

Generated by OpenCVE AI on September 9, 2026 at 08:35 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Sylius to version 2.0.18, 2.1.15, or 2.2.6 and later, all of which contain the channel validation fix.
  • If upgrading is not immediately possible, decorate the PaymentMethodChangerInterface service in the application to re‑implement the necessary channel check before accepting a payment method change.
  • As an additional safeguard, review and adjust globally enabled payment methods to ensure they match the intended channel restrictions for all active channels.

Generated by OpenCVE AI on September 9, 2026 at 08:35 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Github GHSA Github GHSA GHSA-6955-hrm5-c4qp Sylius: Channel-based payment method restriction bypass on shop account orders API endpoint
History

Mon, 14 Sep 2026 13:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 11 Sep 2026 02:30:00 +0000

Type Values Removed Values Added
First Time appeared Sylius
Sylius sylius
Vendors & Products Sylius
Sylius sylius

Tue, 08 Sep 2026 22:30:00 +0000

Type Values Removed Values Added
Description Sylius is an Open Source eCommerce Framework on Symfony. Starting in version 2.0.0 and prior to version 2.0.18, 2.1.15, and 2.2.6, an authorization bypass vulnerability exists in the shop account API. The `PATCH /api/v2/shop/account/orders/{tokenValue}/payments/{paymentId}` endpoint, used by an authenticated shop customer to change the payment method of an order that has been placed but not yet paid (state `STATE_NEW`), does not validate that the chosen payment method is enabled for the order's channel. The equivalent checkout endpoint (`PATCH /api/v2/shop/orders/{tokenValue}/payments/{paymentId}`) correctly rejects out-of-channel payment methods with `HTTP 422`; the account endpoint silently accepts them and returns `HTTP 200`. An authenticated customer can therefore assign any globally enabled payment method to their own placed order, including methods that the store operator has explicitly excluded from that channel. The issue is fixed in versions: 2.0.18, 2.1.15, 2.2.6 and above. As a workaround, decorate the `Sylius\Bundle\ApiBundle\Changer\PaymentMethodChangerInterface` service in the application.
Title Sylius: Channel-based payment method restriction bypass on shop account orders API endpoint
Weaknesses CWE-863
References
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-09-14T12:05:51.544Z

Reserved: 2026-06-09T20:16:59.648Z

Link: CVE-2026-53638

cve-icon Vulnrichment

Updated: 2026-09-14T12:05:47.040Z

cve-icon NVD

Status : Deferred

Published: 2026-09-08T23:17:24.840

Modified: 2026-09-14T13:18:39.900

Link: CVE-2026-53638

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-11T02:15:10Z

Weaknesses