PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-108724 Sylius CVE debrief

CVE-2026-108724 is an authorization bypass vulnerability in Sylius, a popular e-commerce platform, that allows unauthenticated attackers to read unmoderated and rejected product reviews. The vulnerability exists in Sylius versions up to 2.3.0 and is caused by the lack of application of the AcceptedExtension filter to the item operation. This allows attackers to enumerate sequential IDs on the GET /api/v2/shop/product-reviews/{id} endpoint to retrieve review titles, ratings, comments, timestamps, and author first names, bypassing merchant moderation.

Vendor
Sylius
Product
Unknown
CVSS
MEDIUM 6.9
CISA KEV
Not listed in stored evidence
Original CVE published
2026-10-11
Original CVE updated
2026-10-11
Advisory published
2026-10-11
Advisory updated
2026-10-11

Who should care

Defenders responsible for Sylius installations, especially those using versions up to 2.3.0, should be aware of this vulnerability and take steps to verify and mitigate it. This includes operators, platform administrators, vulnerability management teams, and security teams who need to assess exposure, apply patches or mitigations, and monitor for unauthorized access to product reviews.

Why it matters

CVE-2026-108724 is an authorization bypass vulnerability in Sylius that allows unauthenticated attackers to read unmoderated and rejected product reviews. Defenders should prioritize verifying the presence of this vulnerability in their Sylius installations and apply patches or mitigations as available.

  • Verify and restrict access to the /api/v2/shop/product-reviews/{id} endpoint
  • Monitor for unauthorized access to product reviews
  • Apply patches or mitigations as available
  • Assess exposure of sensitive information in product reviews

Technical summary

The vulnerability exists in Sylius versions up to 2.3.0 and is caused by the lack of application of the AcceptedExtension filter to the item operation. This allows attackers to enumerate sequential IDs on the GET /api/v2/shop/product-reviews/{id} endpoint to retrieve review titles, ratings, comments, timestamps, and author first names, bypassing merchant moderation. Affected product deployments should be identified in managed environments, and owners should be assigned for follow-up. Official advisories or CVE records should be reviewed to validate affected scope, severity, and vendor guidance.

Defensive priority

Defenders should prioritize verifying the presence of this vulnerability in their Sylius installations, especially if they are using versions up to 2.3.0, and apply patches or mitigations as available.

Recommended defensive actions

  • Verify the presence of Sylius versions up to 2.3.0 in your environment
  • Apply patches or mitigations as available
  • Monitor for unauthorized access to product reviews
  • Restrict access to the /api/v2/shop/product-reviews/{id} endpoint
  • Review compensating controls for exposed systems while remediation is scheduled and verified
  • Check relevant monitoring, detection, and logs for exposed assets that need extra review
  • Track exceptions, retest remediated assets, and close the item only after evidence is documented

Evidence notes

The CVE record and source item provide details on the vulnerability, including its description, affected versions, and references to additional information. However, the corpus does not provide information on exploitation or specific remediation steps.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-108724 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-108724

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-108724 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-108724

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Sylius through 2.3.0 Authorization Bypass via Shop API Product-Review Endpoint

    Unverified legacy reference

    URL: https://raw.githubusercontent.com/CVEProject/cvelistV5/main/cves/2026/108xxx/CVE-2026-108724.json

    cve_program_cvelist_v5

  • Source reference

    Unverified legacy reference

    URL: https://hackmd.io/@haind/sylius-shop-product-review-item-moderation-bypass

    Supplemental source - third-party-advisory

  • Source reference

    Unverified legacy reference

    URL: https://github.com/Sylius/Sylius/blob/34fc73a9ee89e8cd3f11aa81d0b18ee91f25e8d7/src/Sylius/Bundle/ApiBundle/Doctrine/ORM/QueryExtension/Shop/ProductReview/AcceptedExtension.php

    Supplemental source - technical-description

  • Source reference

    Unverified legacy reference

    URL: https://github.com/Sylius/Sylius/blob/34fc73a9ee89e8cd3f11aa81d0b18ee91f25e8d7/src/Sylius/Bundle/ApiBundle/Resources/config/services/extensions.php

    Supplemental source - technical-description

  • Source reference

    Unverified legacy reference

    URL: https://github.com/Sylius/Sylius

    Supplemental source - product

  • Source reference

    Unverified legacy reference

    URL: https://www.vulncheck.com/advisories/sylius-through-2.3.0-authorization-bypass-via-shop-api-product-review-endpoint

    Supplemental source - third-party-advisory

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.