MEDIUMCVSS 6.5Vulnerability

CVE-2026-68501

Sylius Mollie Plugin provides Mollie payment integration for Sylius applications. Prior to 2.2.8, 3.2.4, and 3.3.1, Sylius Mollie Plugin's GET /{_locale}/thank-you PageRedirectController::thankYouAction and GET /{_locale}/get-code QrCodeAction::fetchQrCodeFromOrder endpoints look up sequential orderId values without ownership or session checks, exposing order tokenValue values that can be used with GET /{_locale}/register-after-checkout/{tokenValue} to view customer first name, last name, and email. This issue is fixed in 2.2.8, 3.2.4, and 3.3.1.

Properties

summary
Sylius Mollie Plugin has unauthenticated IDOR that leaks order token and customer PII
severity
MEDIUM
epss_score
0.00429
cvss_score
6.5
ghsa_published
2026-07-31T16:52:59Z
source_url
https://github.com/advisories/GHSA-x83g-979r-f5fh
ghsa_updated
2026-07-31T16:53:01Z
ghsa_id
GHSA-x83g-979r-f5fh
score
6.5
cve_id
CVE-2026-68501
cvss_vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L
signal_observed_at
2026-09-11T17:54:55+00:00
is_ghsa_only
false
vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L
published_at
2026-07-30T21:18:13.180
last_modified
2026-09-10T20:12:43.783
epss_percentile
0.36326

Related Entities (6)

DESCRIBED_BY (1)

[Source]NVD

ENRICHED_BY (1)

[Source]FIRST EPSS

VULNERABLE_TO (1)

[Software]composer/sylius/mollie-plugin

AFFECTS (1)

[Software]composer/sylius/mollie-plugin

HAS_WEAKNESS (1)

[Weakness]Authorization Bypass Through User-Controlled Key

REPORTED_BY (1)

[Source]GitHub Advisory Database

Explore deeper with Ninja Signal's threat intelligence graph

CVE-2026-68501 (CVSS 6.5) — Ninja Signal Threat Intelligence | Ninja Signal