Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-91154— Missing authentication in Ecommerce Template product cache revalidation allows unauthenticated denial of service

Quick assessment

Affected
MarcosCamara01 Ecommerce Template
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

关键函数缺失身份验证(CWE-306)存在于 MarcosCamara01 电子商务模板中、在提交 ec97209 之前的产品缓存重新验证 Server Action(src/app/actions.ts 中的 revalidateProducts)中。该漏洞允许远程、未认证的攻击者随意强制使整个 storefront 的产品缓存失效。 该文件在文件作用域声明了 ,因此其中导出的每个函数都会编译为一个可通过 POST 调用的 Server Action。 函数调用了 ,但未进行任何会话(session)或角色(ro

CVSS 6.9 · Medium
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-91154

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Missing authentication in Ecommerce Template product cache revalidation allows unauthenticated denial of service
Source: CVE Program / CVE List V5
Vulnerability Description
Missing Authentication for Critical Function (CWE-306) in the product cache revalidation Server Action (src/app/actions.ts, revalidateProducts) in MarcosCamara01 Ecommerce Template before commit ec97209 allows a remote, unauthenticated attacker to force expiration of the entire storefront product cache at will. The file declares "use server" at file scope, so every exported function compiles into a POST-invokable Server Action; revalidateProducts calls updateTag("products") with no session or role check, unlike the read-only actions in the same file which are safe by construction. Two client components under src/components/admin import the function, which causes its Server Action id to be compiled into a public /_next/static chunk that the application's admin middleware (proxy.ts) does not gate, so any unauthenticated user can extract that id from the public bundle and invoke the action directly. With cacheComponents enabled, the entire storefront (home, categories, product pages, search) is served from "use cache" entries produced by getAllProducts, getCategoryProducts and getProduct, all tagged products with an hours-long cacheLife. Repeated unauthenticated invocation of revalidateProducts keeps that cache permanently cold, forcing every visitor's request to read the full product catalog from Postgres instead of serving from cache, degrading storefront availability at near-zero attacker cost.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N
Source: CVE Program / CVE List V5
Vulnerability Type
关键功能的认证机制缺失
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
MarcosCamara01 Ecommerce Template 0 ~ ec97209 -

II. Public POCs for CVE-2026-91154

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-91154

请登录查看更多情报信息。

Other References for CVE-2026-91154 (2)

IV. Related Vulnerabilities

V. Comments for CVE-2026-91154

No comments yet


Leave a comment