HIGHCVSS 7.5Vulnerability

CVE-2026-68500

Sylius Mollie Plugin provides Mollie payment integration for Sylius applications. Prior to 2.2.8, 3.2.4, and 3.3.1, Sylius Mollie Plugin's POST /{_locale}/update-payment payment webhook accepts attacker-controlled id and orderId parameters but does not verify that the Mollie payment belongs to the referenced Sylius order, allowing an unauthenticated attacker with any valid paid Mollie payment ID to mark a victim order as paid without transferring funds for that order. This issue is fixed in 2.2.8, 3.2.4, and 3.3.1.

Properties

summary
Sylius Mollie Plugin vulnerable to payment status forgery via the payment webhook
severity
HIGH
epss_score
0.00382
cvss_score
7.5
ghsa_published
2026-07-31T16:52:39Z
source_url
https://github.com/advisories/GHSA-rc52-c4hv-w89p
ghsa_updated
2026-07-31T16:52:41Z
ghsa_id
GHSA-rc52-c4hv-w89p
score
7.5
cve_id
CVE-2026-68500
cvss_vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
signal_observed_at
2026-09-11T17:54:55+00:00
is_ghsa_only
false
vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
published_at
2026-07-30T21:18:13.007
last_modified
2026-09-10T20:12:43.783
epss_percentile
0.31741

Related Entities (6)

DESCRIBED_BY (1)

[Source]NVD

ENRICHED_BY (1)

[Source]FIRST EPSS

VULNERABLE_TO (1)

[Software]composer/sylius/mollie-plugin

AFFECTS (1)

[Software]composer/sylius/mollie-plugin

HAS_WEAKNESS (1)

[Weakness]Authorization Bypass Through User-Controlled Key

REPORTED_BY (1)

[Source]GitHub Advisory Database

Explore deeper with Ninja Signal's threat intelligence graph

CVE-2026-68500 (CVSS 7.5) — Ninja Signal Threat Intelligence | Ninja Signal