PT-2026-99922 · Unknown · Marcoscamara01 Ecommerce Template

·

CVE-2026-91154

·

Published

2026-09-28

·

Updated

2026-09-28

CVSS v4.0

6.9

Medium

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions MarcosCamara01 Ecommerce Template versions prior to commit ec97209
Description Missing authentication in the product cache revalidation Server Action allows a remote, unauthenticated attacker to force the expiration of the entire storefront product cache. The function revalidateProducts() in src/app/actions.ts calls updateTag("products") without performing session or role checks. Because the file uses the "use server" directive, the function is compiled into a POST-invokable Server Action. The action ID is exposed in a public / next/static chunk, which is not protected by the admin middleware in proxy.ts. When cacheComponents is enabled, the storefront relies on cached entries from getAllProducts(), getCategoryProducts(), and getProduct(). Repeatedly invoking the vulnerable action keeps the cache cold, forcing the application to read the full product catalog from the Postgres database for every request, which degrades storefront availability.
Recommendations Update MarcosCamara01 Ecommerce Template to commit ec97209 or later. As a temporary workaround, restrict access to the revalidateProducts() function by implementing a session or role check within src/app/actions.ts.

Exploit

Fix

DoS

Missing Authentication

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-91154

Affected Products

Marcoscamara01 Ecommerce Template