CVE-2026-100869

CVE-2026-100869 published: Sylius versions before 2.1.16 and 2.2.9 fail to restrict payment request actions in the Shop API endpoint, allowing customers to trigger refunds on completed orders. Attackers with order tokens can submit arbitrary payment actions like refunds that payment ...

View full NVD advisory → ← Back to CVE watch