Description
Missing Authentication for Critical Function (CWE-306) in the product cache revalidation Server Action (src/app/actions.ts, revalidateProducts) in MarcosCamara01 Ecommerce Template before commit ec97209 allows a remote, unauthenticated attacker to force expiration of the entire storefront product cache at will. The file declares "use server" at file scope, so every exported function compiles into a POST-invokable Server Action; revalidateProducts calls updateTag("products") with no session or role check, unlike the read-only actions in the same file which are safe by construction. Two client components under src/components/admin import the function, which causes its Server Action id to be compiled into a public /_next/static chunk that the application's admin middleware (proxy.ts) does not gate, so any unauthenticated user can extract that id from the public bundle and invoke the action directly. With cacheComponents enabled, the entire storefront (home, categories, product pages, search) is served from "use cache" entries produced by getAllProducts, getCategoryProducts and getProduct, all tagged products with an hours-long cacheLife. Repeated unauthenticated invocation of revalidateProducts keeps that cache permanently cold, forcing every visitor's request to read the full product catalog from Postgres instead of serving from cache, degrading storefront availability at near-zero attacker cost.
Published: 2026-09-28
Score: 6.9 Medium
EPSS: n/a
KEV: No
Impact: Unauthenticated Denial of Service
Action: Patch
AI Analysis

Impact

The vulnerability is a missing authentication check in the revalidateProducts server action. Because the action is exported from a file-scoped "use server" module, it is compiled into a public POST-invokable endpoint. An unauthenticated requester can identify the action’s ID in the public JavaScript bundle and call it to trigger updateTag("products"), causing the entire storefront cache to expire. This results in the storefront operating at full database load for an extended period, effectively denying service to legitimate users. The weakness is identified as CWE-306.

Affected Systems

The affected product is MarcosCamara01 Ecommerce Template. All releases prior to the commit ec97209 are vulnerable. The issue is tied to the server action defined in src/app/actions.ts and exposed to client components that import it.

Risk and Exploitability

The vulnerability has a CVSS score of 6.9, indicating medium severity. The EPSS score is not available, and it is not listed in CISA KEV, but the risk remains significant because the attack requires no authentication and a single POST request to the server action. Given the low complexity and the obvious impact of cache exhaustion, a remote attacker can cause widespread service degradation with minimal effort. The likely attack vector is a remote unauthenticated POST request to the server action, triggered by extracting the action ID from the public bundle.

Generated by OpenCVE AI on September 28, 2026 at 16:52 UTC.

Remediation

Vendor Solution

Update to a build including commit ec97209, which moves revalidateProducts out of the file-scoped "use server" module into a server-only module and restricts its only network-reachable caller (GET /api/cron/catalog-sync) with an internal credential check. Do not export unauthenticated mutations from a file-scoped "use server" module; gate any cache-invalidation action behind an admin/session check or remove the client-callable export entirely.


OpenCVE Recommended Actions

  • Apply the vendor‑provided patch that incorporates commit ec97209, which moves the revalidateProducts action into a server‑only module and adds an internal credential check to restrict access.
  • If the patch cannot be applied immediately, modify the code to remove revalidateProducts from the public bundle or wrap it behind a session or role verification before calling updateTag, ensuring only authenticated users can invoke cache invalidation.
  • Implement temporary rate limiting or administrative gating on the server action endpoint to slow repeated unauthenticated requests and mitigate the denial‑of‑service effect.

Generated by OpenCVE AI on September 28, 2026 at 16:52 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 28 Sep 2026 18:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 28 Sep 2026 15:45:00 +0000

Type Values Removed Values Added
Description Missing Authentication for Critical Function (CWE-306) in the product cache revalidation Server Action (src/app/actions.ts, revalidateProducts) in MarcosCamara01 Ecommerce Template before commit ec97209 allows a remote, unauthenticated attacker to force expiration of the entire storefront product cache at will. The file declares "use server" at file scope, so every exported function compiles into a POST-invokable Server Action; revalidateProducts calls updateTag("products") with no session or role check, unlike the read-only actions in the same file which are safe by construction. Two client components under src/components/admin import the function, which causes its Server Action id to be compiled into a public /_next/static chunk that the application's admin middleware (proxy.ts) does not gate, so any unauthenticated user can extract that id from the public bundle and invoke the action directly. With cacheComponents enabled, the entire storefront (home, categories, product pages, search) is served from "use cache" entries produced by getAllProducts, getCategoryProducts and getProduct, all tagged products with an hours-long cacheLife. Repeated unauthenticated invocation of revalidateProducts keeps that cache permanently cold, forcing every visitor's request to read the full product catalog from Postgres instead of serving from cache, degrading storefront availability at near-zero attacker cost.
Title Missing authentication in Ecommerce Template product cache revalidation allows unauthenticated denial of service
First Time appeared Marcoscamara01
Marcoscamara01 ecommerce-template
Weaknesses CWE-306
CPEs cpe:2.3:a:marcoscamara01:ecommerce-template:*:*:*:*:*:*:*:*
Vendors & Products Marcoscamara01
Marcoscamara01 ecommerce-template
References
Metrics cvssV4_0

{'score': 6.9, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N'}


Subscriptions

Marcoscamara01 Ecommerce-template
cve-icon MITRE

Status: PUBLISHED

Assigner: Secur0

Published:

Updated: 2026-09-28T17:52:40.759Z

Reserved: 2026-09-14T21:05:54.953Z

Link: CVE-2026-91154

cve-icon Vulnrichment

Updated: 2026-09-28T17:52:36.424Z

cve-icon NVD

Status : Received

Published: 2026-09-28T16:17:17.110

Modified: 2026-09-28T18:17:26.467

Link: CVE-2026-91154

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-28T17:00:05Z

Weaknesses
  • CWE-306

    Missing Authentication for Critical Function