A Sylius Customer Login Could Open the Admin API
Sylius disclosed on 2 September that a shop customer’s token could be accepted by its Admin API. Two accompanying advisories cover password-reset links and payment totals. These are previously missed disclosures, revalidated after their records were indexed on 27 September.
For operators, the review has two tracks: who received administrative access, and whether the money captured matches the orders marked paid. Closing an authentication flaw does not reconcile historical orders.
A shop token crossed into the Admin API
CVE-2026-100871 affects Sylius releases before 1.12.25, 1.13.17, 1.14.20, 2.1.16 and 2.2.9. The vendor says the Admin and Shop API firewalls signed tokens with the same key, but the tokens did not include an audience or firewall identifier.
The attack prerequisites are that the API is enabled, shop registration is available and the targeted administrator has API access. An attacker who knows that administrator’s email address can register an ordinary shop account with the same address, sign in using the attacker’s own password and present the resulting token to the Admin API.
The genuine reset email pointed to the attacker’s host
CVE-2026-100870 affects the same version ranges. The primary advisory says Sylius built an absolute administrator password-reset link using the request’s Host header unless the deployment supplied its own trusted-host configuration.
The advisory’s attack path lets an unauthenticated attacker request a reset for a known administrator address and supply a forged host. The resulting email is otherwise genuine, but its link sends the valid token to the attacker’s domain. If the administrator follows it, the attacker can reuse the token against the real shop and set a new password.
The payment gateway captured less than the order showed
CVE-2026-100872 affects Sylius 2.x releases before 2.1.16 and 2.2.9. The payment advisory explains that cart recalculation could rewrite the recorded payment amount to the order’s new total after a gateway transaction had begun.
The payment advisory shows a guest starting with a small legitimate purchase, letting the gateway capture that amount, then enlarging the same order. When the gateway later reports success, the vulnerable application checks the status but not whether the captured amount matches the updated order.
Patch matrix
| Sylius branch | First fixed release | Covered issues |
|---|---|---|
| 1.12 | 1.12.25 | JWT confusion and reset-host poisoning |
| 1.13 | 1.13.17 | JWT confusion and reset-host poisoning |
| 1.14 | 1.14.20 | JWT confusion and reset-host poisoning |
| 2.1 | 2.1.16 | All three issues |
| 2.2 | 2.2.9 | All three issues |
What operators should do
- Install the fixed release for the deployed branch. Do not treat a web-application firewall as a substitute for the authentication fixes.
- Set trusted hosts. Restrict accepted Host headers at the application and reverse-proxy layers.
- Prepare every API client to authenticate again. The JWT fix rejects tokens issued before the upgrade, so customer and administrator clients need new tokens.
- Search for duplicate identities. Identify shop accounts using administrator email addresses, especially accounts created shortly before administrative activity.
- Audit reset requests. Review Host values and destination domains associated with administrator reset traffic.
- Reconcile money with orders. Compare gateway captures with final order totals and investigate mismatches, not merely completed payment states.
The reviewed advisories do not report malicious exploitation in the wild. All three flaws cross a business-critical trust boundary using ordinary platform features. BlackTree’s analysis of a different Adobe Commerce attack path shows why shop operators need to reconcile identity, application state and payment records rather than treating patch status as the only control.
Sources
- Sylius security release overview, published 2 September 2026. No publication time is provided.
- Sylius JWT audience-confusion advisory, published 2 September 2026 at 13:57:44 UTC, 15:57:44 CEST.
- Sylius reset-host advisory, published 2 September 2026 at 13:57:50 UTC, 15:57:50 CEST.
- Sylius payment-amount advisory, published 2 September 2026 at 13:57:39 UTC, 15:57:39 CEST.
- NVD published the three corresponding records on 27 September 2026 at 13:16:38 UTC, 15:16:38 CEST. Those records provided the new indexing signal; they were not the original disclosure.


