PatchSiren cyber security CVE debrief
CVE-2026-108724 Sylius CVE debrief
CVE-2026-108724 is an authorization bypass vulnerability in Sylius, a popular e-commerce platform, that allows unauthenticated attackers to read unmoderated and rejected product reviews. The vulnerability exists in Sylius versions up to 2.3.0 and is caused by the lack of application of the AcceptedExtension filter to the item operation. This allows attackers to enumerate sequential IDs on the GET /api/v2/shop/product-reviews/{id} endpoint to retrieve review titles, ratings, comments, timestamps, and author first names, bypassing merchant moderation.
- Vendor
- Sylius
- Product
- Unknown
- CVSS
- MEDIUM 6.9
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-10-11
- Original CVE updated
- 2026-10-11
- Advisory published
- 2026-10-11
- Advisory updated
- 2026-10-11
Who should care
Defenders responsible for Sylius installations, especially those using versions up to 2.3.0, should be aware of this vulnerability and take steps to verify and mitigate it. This includes operators, platform administrators, vulnerability management teams, and security teams who need to assess exposure, apply patches or mitigations, and monitor for unauthorized access to product reviews.
Why it matters
CVE-2026-108724 is an authorization bypass vulnerability in Sylius that allows unauthenticated attackers to read unmoderated and rejected product reviews. Defenders should prioritize verifying the presence of this vulnerability in their Sylius installations and apply patches or mitigations as available.
- Verify and restrict access to the /api/v2/shop/product-reviews/{id} endpoint
- Monitor for unauthorized access to product reviews
- Apply patches or mitigations as available
- Assess exposure of sensitive information in product reviews
Technical summary
The vulnerability exists in Sylius versions up to 2.3.0 and is caused by the lack of application of the AcceptedExtension filter to the item operation. This allows attackers to enumerate sequential IDs on the GET /api/v2/shop/product-reviews/{id} endpoint to retrieve review titles, ratings, comments, timestamps, and author first names, bypassing merchant moderation. Affected product deployments should be identified in managed environments, and owners should be assigned for follow-up. Official advisories or CVE records should be reviewed to validate affected scope, severity, and vendor guidance.
Defensive priority
Defenders should prioritize verifying the presence of this vulnerability in their Sylius installations, especially if they are using versions up to 2.3.0, and apply patches or mitigations as available.
Recommended defensive actions
- Verify the presence of Sylius versions up to 2.3.0 in your environment
- Apply patches or mitigations as available
- Monitor for unauthorized access to product reviews
- Restrict access to the /api/v2/shop/product-reviews/{id} endpoint
- Review compensating controls for exposed systems while remediation is scheduled and verified
- Check relevant monitoring, detection, and logs for exposed assets that need extra review
- Track exceptions, retest remediated assets, and close the item only after evidence is documented
Evidence notes
The CVE record and source item provide details on the vulnerability, including its description, affected versions, and references to additional information. However, the corpus does not provide information on exploitation or specific remediation steps.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-108724 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-108724
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-108724 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-108724
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Sylius through 2.3.0 Authorization Bypass via Shop API Product-Review Endpoint
Unverified legacy reference
URL: https://raw.githubusercontent.com/CVEProject/cvelistV5/main/cves/2026/108xxx/CVE-2026-108724.json
cve_program_cvelist_v5
-
Source reference
Unverified legacy reference
URL: https://hackmd.io/@haind/sylius-shop-product-review-item-moderation-bypass
Supplemental source - third-party-advisory
-
Source reference
Unverified legacy reference
URL: https://github.com/Sylius/Sylius/blob/34fc73a9ee89e8cd3f11aa81d0b18ee91f25e8d7/src/Sylius/Bundle/ApiBundle/Doctrine/ORM/QueryExtension/Shop/ProductReview/AcceptedExtension.php
Supplemental source - technical-description
-
Source reference
Unverified legacy reference
URL: https://github.com/Sylius/Sylius/blob/34fc73a9ee89e8cd3f11aa81d0b18ee91f25e8d7/src/Sylius/Bundle/ApiBundle/Resources/config/services/extensions.php
Supplemental source - technical-description
-
Source reference
Unverified legacy reference
URL: https://github.com/Sylius/Sylius
Supplemental source - product
-
Source reference
Unverified legacy reference
URL: https://www.vulncheck.com/advisories/sylius-through-2.3.0-authorization-bypass-via-shop-api-product-review-endpoint
Supplemental source - third-party-advisory
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.