CVE-2026-31820: 
PHP vulnerability analysis and mitigation

Overview

CVE-2026-31820 is an authenticated Insecure Direct Object Reference (IDOR) vulnerability in Sylius, an open-source eCommerce framework built on Symfony. The flaw exists in multiple shop LiveComponents — specifically the Checkout address FormComponent, Cart WidgetComponent, and Cart SummaryComponent — where unvalidated resource IDs are accepted via #[LiveArg] parameters without ownership verification. Affected versions include Sylius 2.0.0–2.0.15, 2.1.0–2.1.11, and 2.2.0–2.2.2. The vulnerability was published on March 9, 2026 (GitHub Advisory) and March 10, 2026 (NVD), and carries a CVSS v3.1 score of 6.5 (Medium) and a CVSS v4.0 score of 7.1 (High) (GitHub Advisory, Sylius Advisory).

Technical details

The root cause is CWE-639 (Authorization Bypass Through User-Controlled Key): Symfony LiveComponent #[LiveArg] parameters are fully user-controlled and not protected by the @checksum mechanism that guards #[LiveProp] values. Three vulnerable actions exist: (1) addressFieldUpdated in the Checkout address FormComponent accepts an addressId and calls ->find() without verifying the address belongs to the authenticated customer; (2) refreshCart in the Cart WidgetComponent accepts a cartId and loads any order directly from the repository; (3) refreshCart in the Cart SummaryComponent similarly loads any order by ID. Because the sylius_order table stores both active carts (state=cart) and completed orders (state=new/fulfilled) in a shared ID space, the cart IDOR exposes data across all order states, not just active carts (GitHub Advisory, Sylius Advisory).

Impact

A successfully authenticated attacker can enumerate sequential or guessable order/address IDs to access other customers' personally identifiable information (PII) and financial data. The Checkout address component exposes first name, last name, company, phone number, street, city, postcode, and country of arbitrary users. The Cart Widget and Cart Summary components expose order totals, item counts, subtotals, discounts, shipping costs, and tax details for both active carts and completed orders across the entire customer base. There is no integrity or availability impact, but the confidentiality breach is high and could facilitate targeted phishing, fraud, or regulatory violations (e.g., GDPR) (GitHub Advisory).

Exploitability

No public proof-of-concept exploit code is known to exist, and there is no evidence of in-the-wild exploitation at this time (Feedly). The vulnerability requires only a low-privilege authenticated account (any registered shop customer), making it accessible to a broad attacker population. The EPSS score is approximately 0.021% (6th percentile), indicating a low near-term exploitation probability. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. The vulnerability was responsibly disclosed by Peter Stöckli (@p-) and Man Yue Mo (@m-y-mo) of the GitHub Security Lab (Sylius Advisory).

Exploitation steps

  1. Authenticate: Register or log in as a standard customer on a vulnerable Sylius storefront (versions 2.0.0–2.0.15, 2.1.0–2.1.11, or 2.2.0–2.2.2).
  2. Identify LiveComponent endpoints: Using browser developer tools or a proxy (e.g., Burp Suite), observe LiveComponent AJAX requests made during checkout or cart interactions to identify the endpoint handling #[LiveArg] parameters (typically a POST to a Symfony UX LiveComponent route).
  3. Enumerate address IDs (IDOR #1): Intercept or craft a request to the addressFieldUpdated action of the Checkout address FormComponent, substituting the addressId LiveArg with sequential integers (e.g., 1, 2, 3, ...) to retrieve other users' address PII.
  4. Enumerate cart/order IDs (IDOR #2 & #3): Intercept or craft requests to the refreshCart action of the Cart WidgetComponent or Cart SummaryComponent, substituting the cartId LiveArg with sequential integers to retrieve order totals, item counts, discounts, shipping costs, and tax details for arbitrary orders — including completed orders.
  5. Harvest data: Automate enumeration using a script to iterate over a range of IDs, collecting PII and financial data from the JSON responses returned by the LiveComponent actions. (GitHub Advisory, Sylius Advisory)

Indicators of compromise

  • Network: Unusual volume of POST requests to Symfony UX LiveComponent endpoints (e.g., /_components/sylius_shop:checkout:address:form or /_components/sylius_shop:cart:widget) from a single authenticated session, with rapidly incrementing addressId or cartId values in the request body.
  • Logs: Application or web server access logs showing repeated LiveComponent action requests (addressFieldUpdated, refreshCart) with sequential or enumerated integer IDs from the same user session or IP address.
  • Logs: Symfony application logs showing high-frequency ->find() calls on the address or order repository from a single customer context within a short time window.
  • Behavior: A single authenticated user account triggering LiveComponent refresh actions far more frequently than typical user interaction patterns would suggest (e.g., hundreds of requests per minute).

Mitigation and workarounds

Upgrade Sylius to the patched versions: 2.0.16 (for the 2.0.x line), 2.1.12 (for the 2.1.x line), or 2.2.3 (for the 2.2.x line). For teams unable to upgrade immediately, the advisory provides a detailed workaround involving overriding the three vulnerable LiveComponent classes at the project level to add ownership validation: use findOneByCustomer() instead of find() in the address FormComponent, and ignore the user-supplied cartId in both cart components by always loading the cart from the session context. After applying overrides, register the new service definitions in config/services.yaml and clear the Symfony cache with php bin/console cache:clear (Sylius Advisory, GitHub Advisory).

Community reactions

The vulnerability was responsibly disclosed by Peter Stöckli (@p-) and Man Yue Mo (@m-y-mo) of the GitHub Security Lab, who are credited in the official Sylius advisory. Sylius published a security blog post alongside the advisory. No significant broader media coverage or notable community controversy has been identified beyond standard vulnerability tracking (Sylius Blog, Sylius Advisory).

Additional resources


Source: This report was generated using AI

Related PHP vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-55224HIGH8.7
  • PHP logoPHP
  • mineadmin/mineadmin
NoYesSep 30, 2026
CVE-2026-103111HIGH7.6
  • MariaDB Server logoMariaDB Server
  • mariadb11.8-server
NoYesSep 30, 2026
GHSA-3q6v-r5mr-hxv8HIGH7.5
  • PHP logoPHP
  • league/commonmark
NoYesSep 30, 2026
GHSA-97jj-33gv-5xf9MEDIUM6.1
  • PHP logoPHP
  • league/commonmark
NoYesSep 30, 2026
CVE-2026-104181MEDIUM5.4
  • PHP logoPHP
  • filament/filament
NoYesOct 01, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management