CVE-2026-31820 | Sylius up to 2.0.15/2.1.11/2.2.2 Cart Widget find authorization (GHSA-2xc6-348p-c2x6)
A vulnerability was found in Sylius up to 2.0.15/2.1.11/2.2.2. It has been declared as problematic. This affects the function find of the component Cart Widget. The manipulation results in authorization bypass.
This vulnerability is known as CVE-2026-31820. It is possible to launch the attack remotely. No exploit is available.
It is recommended to upgrade the affected component.