Advisory Database
  • Advisories
  • Dependency Scanning
  1. composer
  2. ›
  3. sylius/mollie-plugin
  4. ›
  5. CVE-2026-68501

CVE-2026-68501: Sylius Mollie Plugin has unauthenticated IDOR that leaks order token and customer PII

July 31, 2026

Two unauthenticated Mollie shop endpoints look up orders by a sequential integer orderId with no ownership or session check. Chained, they expose customer PII.

GET /{_locale}/thank-you (PageRedirectController::thankYouAction, route sylius_mollie_shop_thank_you_page_redirect) loads the order with findOneBy(['id' => $orderId]) and returns a 302 whose Location header carries that order’s tokenValue. Any orderId thus yields that order’s token. A non-existent id dereferences null and returns a 500. The handler also writes the raw orderId into the session.

GET /{_locale}/get-code (QrCodeAction::fetchQrCodeFromOrder, route sylius_mollie_shop_get_qr_code) runs the same lookup and returns the order’s QR code and id as JSON, ignoring the session cart; this is where the front-end got the integer id. A bad id 500s here too.

That tokenValue is the order’s only access control. Passed to the Sylius core page GET /{_locale}/register-after-checkout/{tokenValue} it returns a form pre-filled with the customer’s first name, last name and email. The full attack: enumerate orderId, read the token from the redirect, read the PII, at roughly a 1-in-71 hit rate for guest orders. register-after-checkout is Sylius core, not the plugin, and trusts the token by design, so the leak is what must be fixed.

None of the plugin endpoints require a login, session or CSRF token.

References

  • github.com/Sylius/MolliePlugin/commit/01316b3ad3cf82e3c5ad160115d0a2cf89174e49
  • github.com/Sylius/MolliePlugin/commit/153c754486b1bc597b67a90ac07ef71cd7958267
  • github.com/Sylius/MolliePlugin/commit/d1f7753e92106e8bf3bedcfc61b02ea7b8e1c38a
  • github.com/Sylius/MolliePlugin/pull/351
  • github.com/Sylius/MolliePlugin/pull/352
  • github.com/Sylius/MolliePlugin/pull/354
  • github.com/Sylius/MolliePlugin/releases/tag/v2.2.8
  • github.com/Sylius/MolliePlugin/releases/tag/v3.2.4
  • github.com/Sylius/MolliePlugin/releases/tag/v3.3.1
  • github.com/Sylius/MolliePlugin/security/advisories/GHSA-x83g-979r-f5fh
  • github.com/advisories/GHSA-x83g-979r-f5fh
  • nvd.nist.gov/vuln/detail/CVE-2026-68501

Code Behaviors & Features

Detect and mitigate CVE-2026-68501 with GitLab Dependency Scanning

Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →

Affected versions

All versions before 2.2.8, all versions starting from 3.0.0 before 3.2.4, all versions starting from 3.3.0 before 3.3.1

Fixed versions

  • 2.2.8
  • 3.2.4
  • 3.3.1

Solution

Upgrade to versions 2.2.8, 3.2.4, 3.3.1 or above.

Impact 6.5 MEDIUM

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L

Learn more about CVSS

Weakness

  • CWE-639: Authorization Bypass Through User-Controlled Key

Source file

packagist/sylius/mollie-plugin/CVE-2026-68501.yml

Spotted a mistake? Edit the file on GitLab.

  • Site Repo
  • About GitLab
  • Terms
  • Privacy Statement
  • Contact

Page generated Sat, 08 Aug 2026 00:17:23 +0000.