CVE-2026-68500 Details
Description
Sylius Mollie Plugin provides Mollie payment integration for Sylius applications. Prior to 2.2.8, 3.2.4, and 3.3.1, Sylius Mollie Plugin's POST /{_locale}/update-payment payment webhook accepts attacker-controlled id and orderId parameters but does not verify that the Mollie payment belongs to the referenced Sylius order, allowing an unauthenticated attacker with any valid paid Mollie payment ID to mark a victim order as paid without transferring funds for that order. This issue is fixed in 2.2.8, 3.2.4, and 3.3.1.
A vulnerability in the Sylius Mollie Plugin's payment webhook endpoint allows unauthenticated attackers to manipulate order payment statuses. The issue arises because the webhook accepts attacker-controlled parameters without proper validation. Specifically, the Mollie payment ID and order ID can be exploited to falsely mark an order as paid, without any actual funds being transferred. This vulnerability affects Sylius Mollie Plugin versions prior to 2.2.8, 3.2.4, and 3.3.1.
Users can upgrade to Sylius Mollie Plugin versions 2.2.8, 3.2.4, or 3.3.1, where this vulnerability has been fixed. Instructions for updating the plugin can be found in the release notes on the Sylius Mollie Plugin GitHub repository.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Jul 30, 2026CISA-ADP
Assessed Jul 31, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-639 | Authorization Bypass Through User-Controlled Key | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| Sylius Mollie Plugin | <= 2.2.0 (semver) < 2.2.8 (semver) >= 3.2.0 (semver) < 3.2.4 (semver) >= 3.3.0 (semver) < 3.3.1 (semver) |
CPE
Remediation
| |
Change History
2 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jul 31, 2026 | CVE Modified | CISA-ADP |
| Jul 30, 2026 | New CVE Received | [email protected] |
Volerion