Analysis and contextual insights are available on OpenCVE Cloud.
Vendor Solution
Update to a build including commit ec97209, which moves revalidateProducts out of the file-scoped "use server" module into a server-only module and restricts its only network-reachable caller (GET /api/cron/catalog-sync) with an internal credential check. Do not export unauthenticated mutations from a file-scoped "use server" module; gate any cache-invalidation action behind an admin/session check or remove the client-callable export entirely.
Tracking
Sign in to view the affected projects.
No advisories yet.
Mon, 28 Sep 2026 18:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 28 Sep 2026 15:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Missing Authentication for Critical Function (CWE-306) in the product cache revalidation Server Action (src/app/actions.ts, revalidateProducts) in MarcosCamara01 Ecommerce Template before commit ec97209 allows a remote, unauthenticated attacker to force expiration of the entire storefront product cache at will. The file declares "use server" at file scope, so every exported function compiles into a POST-invokable Server Action; revalidateProducts calls updateTag("products") with no session or role check, unlike the read-only actions in the same file which are safe by construction. Two client components under src/components/admin import the function, which causes its Server Action id to be compiled into a public /_next/static chunk that the application's admin middleware (proxy.ts) does not gate, so any unauthenticated user can extract that id from the public bundle and invoke the action directly. With cacheComponents enabled, the entire storefront (home, categories, product pages, search) is served from "use cache" entries produced by getAllProducts, getCategoryProducts and getProduct, all tagged products with an hours-long cacheLife. Repeated unauthenticated invocation of revalidateProducts keeps that cache permanently cold, forcing every visitor's request to read the full product catalog from Postgres instead of serving from cache, degrading storefront availability at near-zero attacker cost. | |
| Title | Missing authentication in Ecommerce Template product cache revalidation allows unauthenticated denial of service | |
| First Time appeared |
Marcoscamara01
Marcoscamara01 ecommerce-template |
|
| Weaknesses | CWE-306 | |
| CPEs | cpe:2.3:a:marcoscamara01:ecommerce-template:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Marcoscamara01
Marcoscamara01 ecommerce-template |
|
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: Secur0
Published:
Updated: 2026-09-28T17:52:40.759Z
Reserved: 2026-09-14T21:05:54.953Z
Link: CVE-2026-91154
Updated: 2026-09-28T17:52:36.424Z
Status : Received
Published: 2026-09-28T16:17:17.110
Modified: 2026-09-28T18:17:26.467
Link: CVE-2026-91154
No data.
OpenCVE Enrichment
Updated: 2026-09-28T17:00:05Z