What is CVE-2026-68500?
CVE-2026-68500 is a vulnerability in the Sylius Mollie Plugin payment webhook. The POST /{_locale}/update-payment endpoint accepts attacker-controlled id and orderId parameters without verifying if the Mollie payment belongs to the order, allowing potential manipulation. Versions prior to 2.2.8, 3.2.4, and 3.3.1 are affected — immediate update is recommended.
Azərbaycanca: CVE-2026-68500 Sylius Mollie Plugin ödəniş vebhookunda zəiflikdir. /{_locale}/update-payment endpoint-id attacker tərəfindən idarə olunan id və orderId parametrlərini yoxlamadan qəbul edir, bu da ödənişin sifarişə aid olmadığı hallarda manipulyasiyaya imkan verir. 2.2.8, 3.2.4 və 3.3.1 versiyalarından əvvəlki versiyalar təsirlənir — təcili yenilənmə tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-862
FAQ2
What functionality of the Sylius Mollie Plugin does CVE-2026-68500 affect?
This vulnerability affects the payment webhook, specifically the `POST /{_locale}/update-payment` endpoint. Since the endpoint does not properly validate attacker-controlled `id` and `orderId` parameters, it does not verify whether the Mollie payment actually belongs to the order.
Which versions need to be upgraded to protect against CVE-2026-68500?
All versions prior to 2.2.8, 3.2.4, and 3.3.1 are affected. Immediate upgrade to these versions or newer is recommended.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.