Medium severity5.3NVD Advisory· Published Oct 11, 2026
CVE-2026-108724
CVE-2026-108724
Description
Sylius through 2.3.0 contains an authorization bypass vulnerability that allows unauthenticated attackers to read unmoderated and rejected product reviews because the AcceptedExtension filter is not applied to the item operation. Attackers can enumerate sequential ids on GET /api/v2/shop/product-reviews/{id} to retrieve review titles, ratings, comments, timestamps and author first names, bypassing merchant moderation.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
1Patches
Vulnerability mechanics
References
4- github.com/Sylius/Sylius/blob/34fc73a9ee89e8cd3f11aa81d0b18ee91f25e8d7/src/Sylius/Bundle/ApiBundle/Doctrine/ORM/QueryExtension/Shop/ProductReview/AcceptedExtension.phpnvd
- github.com/Sylius/Sylius/blob/34fc73a9ee89e8cd3f11aa81d0b18ee91f25e8d7/src/Sylius/Bundle/ApiBundle/Resources/config/services/extensions.phpnvd
- hackmd.io/@haind/sylius-shop-product-review-item-moderation-bypassnvd
- www.vulncheck.com/advisories/sylius-through-2.3.0-authorization-bypass-via-shop-api-product-review-endpointnvd
News mentions
0No linked articles in our index yet.