PT-2026-99542 · Sylius · Sylius

·

CVE-2026-100872

·

Published

2026-09-27

·

Updated

2026-09-28

CVSS v4.0

8.7

High

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Sylius versions prior to 2.1.16 Sylius versions prior to 2.2.9
Description An issue exists where payment amounts are not validated during cart recalculation. This allows unauthenticated attackers to modify order totals after a gateway transaction has been initiated. An attacker can pay a small amount, increase the order value after the gateway capture, and the system will mark the inflated order as fully paid despite the gateway only capturing the original smaller amount.
Recommendations Update to version 2.1.16 or later. Update to version 2.2.9 or later.

Exploit

Fix

Insufficient Verification of Data Authenticity

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-100872
GHSA-VV4H-Q2X8-74G4

Affected Products

Sylius