CVE-2026-100871 | Sylius up to 2.2.8 JWT Token Generation privileges management

SecurityVulns

A vulnerability marked as critical has been reported in Sylius up to 1.12.24/1.13.16/1.14.19/2.1.15/2.2.8. This vulnerability affects unknown code of the component JWT Token Generation. The manipulation leads to improper privilege management.

This vulnerability is uniquely identified as CVE-2026-100871. The attack is possible to be carried out remotely. No exploit exists.

It is suggested to upgrade the affected component.VulDB Recent EntriesRead More