CVE-2026-31820 is an authenticated Insecure Direct Object Reference (IDOR) vulnerability affecting Sylius, an Open Source eCommerce Framework, specifically within its LiveComponents. This flaw allows an authenticated attacker to access sensitive personal and order information belonging to other users by manipulating unvalidated resource IDs. Rated Medium with a CVSS score of 6.5, the vulnerability has a network attack vector and low attack complexity, requiring only low privileges for exploitation. It leads to a high impact on confidentiality, exposing data such as names, addresses, phone numbers, and full order details from both active carts and completed orders. While there is no evidence of active exploitation, nor public exploit code available, the vulnerability has been publicly disclosed and discussed in one article, necessitating updates to Sylius versions 2.0.16, 2.1.12, 2.2.3, or higher.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 2.0.0, < 2.0.16CPE matchmatch criteria | cpe:2.3:a:sylius:sylius:*:*:*:*:*:*:*:* | ||
>= 2.1.0, < 2.1.12CPE matchmatch criteria | cpe:2.3:a:sylius:sylius:*:*:*:*:*:*:*:* | ||
>= 2.2.0, < 2.2.3CPE matchmatch criteria | cpe:2.3:a:sylius:sylius:*:*:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.