{"api_version":"1","generated_at":"2026-10-01T11:10:45+00:00","cve":"CVE-2026-91154","urls":{"html":"https://cve.report/CVE-2026-91154","api":"https://cve.report/api/cve/CVE-2026-91154.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2026-91154","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2026-91154"},"summary":{"title":"Missing authentication in Ecommerce Template product cache revalidation allows unauthenticated denial of service","description":"Missing Authentication for Critical Function (CWE-306) in the product cache revalidation Server Action (src/app/actions.ts, revalidateProducts) in MarcosCamara01 Ecommerce Template before commit ec97209 allows a remote, unauthenticated attacker to force expiration of the entire storefront product cache at will. The file declares \"use server\" at file scope, so every exported function compiles into a POST-invokable Server Action; revalidateProducts calls updateTag(\"products\") with no session or role check, unlike the read-only actions in the same file which are safe by construction. Two client components under src/components/admin import the function, which causes its Server Action id to be compiled into a public /_next/static chunk that the application's admin middleware (proxy.ts) does not gate, so any unauthenticated user can extract that id from the public bundle and invoke the action directly. With cacheComponents enabled, the entire storefront (home, categories, product pages, search) is served from \"use cache\" entries produced by getAllProducts, getCategoryProducts and getProduct, all tagged products with an hours-long cacheLife. Repeated unauthenticated invocation of revalidateProducts keeps that cache permanently cold, forcing every visitor's request to read the full product catalog from Postgres instead of serving from cache, degrading storefront availability at near-zero attacker cost.","state":"PUBLISHED","assigner":"Secur0","published_at":"2026-09-28 16:17:17","updated_at":"2026-09-29 21:32:59"},"problem_types":["CWE-306","CWE-306 CWE-306 Missing Authentication for Critical Function"],"metrics":[{"version":"4.0","source":"4daa8cea-433a-44bd-9456-53b127fc289a","type":"Secondary","score":"6.9","severity":"MEDIUM","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","data":{"version":"4.0","vectorString":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","baseScore":6.9,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","attackRequirements":"NONE","privilegesRequired":"NONE","userInteraction":"NONE","vulnConfidentialityImpact":"NONE","vulnIntegrityImpact":"NONE","vulnAvailabilityImpact":"LOW","subConfidentialityImpact":"NONE","subIntegrityImpact":"NONE","subAvailabilityImpact":"NONE","exploitMaturity":"NOT_DEFINED","confidentialityRequirement":"NOT_DEFINED","integrityRequirement":"NOT_DEFINED","availabilityRequirement":"NOT_DEFINED","modifiedAttackVector":"NOT_DEFINED","modifiedAttackComplexity":"NOT_DEFINED","modifiedAttackRequirements":"NOT_DEFINED","modifiedPrivilegesRequired":"NOT_DEFINED","modifiedUserInteraction":"NOT_DEFINED","modifiedVulnConfidentialityImpact":"NOT_DEFINED","modifiedVulnIntegrityImpact":"NOT_DEFINED","modifiedVulnAvailabilityImpact":"NOT_DEFINED","modifiedSubConfidentialityImpact":"NOT_DEFINED","modifiedSubIntegrityImpact":"NOT_DEFINED","modifiedSubAvailabilityImpact":"NOT_DEFINED","Safety":"NOT_DEFINED","Automatable":"NOT_DEFINED","Recovery":"NOT_DEFINED","valueDensity":"NOT_DEFINED","vulnerabilityResponseEffort":"NOT_DEFINED","providerUrgency":"NOT_DEFINED"}},{"version":"4.0","source":"CNA","type":"CVSS","score":"6.9","severity":"MEDIUM","vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N","data":{"Automatable":"NOT_DEFINED","Recovery":"NOT_DEFINED","Safety":"NOT_DEFINED","attackComplexity":"LOW","attackRequirements":"NONE","attackVector":"NETWORK","baseScore":6.9,"baseSeverity":"MEDIUM","exploitMaturity":"NOT_DEFINED","privilegesRequired":"NONE","providerUrgency":"NOT_DEFINED","subAvailabilityImpact":"NONE","subConfidentialityImpact":"NONE","subIntegrityImpact":"NONE","userInteraction":"NONE","valueDensity":"NOT_DEFINED","vectorString":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N","version":"4.0","vulnAvailabilityImpact":"LOW","vulnConfidentialityImpact":"NONE","vulnIntegrityImpact":"NONE","vulnerabilityResponseEffort":"NOT_DEFINED"}}],"references":[{"url":"https://github.com/MarcosCamara01/ecommerce-template/commit/ec97209e6c7663cba7b5164468d6946cbfe2f19a","name":"https://github.com/MarcosCamara01/ecommerce-template/commit/ec97209e6c7663cba7b5164468d6946cbfe2f19a","refsource":"4daa8cea-433a-44bd-9456-53b127fc289a","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://secur0.com/en/cna/cve-list/cve-2026-91154-missing-authentication-ecommerce-template-cache-revalidation-dos","name":"https://secur0.com/en/cna/cve-list/cve-2026-91154-missing-authentication-ecommerce-template-cache-revalidation-dos","refsource":"4daa8cea-433a-44bd-9456-53b127fc289a","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://www.cve.org/CVERecord?id=CVE-2026-91154","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-91154","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"MarcosCamara01","product":"Ecommerce Template","version":"affected ec97209 custom","platforms":[]}],"timeline":[],"solutions":[{"source":"CNA","title":"","value":"Update to a build including commit ec97209, which moves revalidateProducts out of the file-scoped \"use server\" module into a server-only module and restricts its only network-reachable caller (GET /api/cron/catalog-sync) with an internal credential check. Do not export unauthenticated mutations from a file-scoped \"use server\" module; gate any cache-invalidation action behind an admin/session check or remove the client-callable export entirely.","time":"","lang":"en"}],"workarounds":[],"exploits":[],"credits":[{"source":"CNA","value":"Robert Mihaila","lang":"en"},{"source":"CNA","value":"Amirreza Fadaeizadeh Bidari","lang":"en"},{"source":"CNA","value":"Dario Rivas Quero","lang":"en"},{"source":"CNA","value":"Secur0 CNA","lang":"en"}],"nvd_cpes":[],"vendor_comments":[],"enrichments":{"kev":null,"epss":{"cve_year":"2026","cve_id":"91154","cve":"CVE-2026-91154","epss":"0.003940000","percentile":"0.310190000","score_date":"2026-09-29","updated_at":"2026-09-30 00:11:20"},"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"metrics":[{"other":{"content":{"id":"CVE-2026-91154","options":[{"Exploitation":"none"},{"Automatable":"yes"},{"Technical Impact":"partial"}],"role":"CISA Coordinator","timestamp":"2026-09-28T17:52:26.669048Z","version":"2.0.3"},"type":"ssvc"}}],"providerMetadata":{"dateUpdated":"2026-09-28T17:52:40.759Z","orgId":"134c704f-9b21-4f2e-91b3-4a467353bcc0","shortName":"CISA-ADP"},"title":"CISA ADP Vulnrichment"}],"cna":{"affected":[{"defaultStatus":"unaffected","modules":["Product cache revalidation Server Action"],"product":"Ecommerce Template","programFiles":["src/app/actions.ts"],"repo":"https://github.com/MarcosCamara01/ecommerce-template","vendor":"MarcosCamara01","versions":[{"lessThan":"ec97209","status":"affected","version":"0","versionType":"custom"}]}],"cpeApplicability":[{"nodes":[{"cpeMatch":[{"criteria":"cpe:2.3:a:marcoscamara01:ecommerce-template:*:*:*:*:*:*:*:*","versionEndExcluding":"ec97209","versionStartIncluding":"0","vulnerable":true}],"negate":false,"operator":"OR"}],"operator":"OR"}],"credits":[{"lang":"en","type":"finder","value":"Robert Mihaila"},{"lang":"en","type":"finder","value":"Amirreza Fadaeizadeh Bidari"},{"lang":"en","type":"analyst","value":"Dario Rivas Quero"},{"lang":"en","type":"coordinator","value":"Secur0 CNA"}],"descriptions":[{"lang":"en","supportingMedia":[{"base64":false,"type":"text/html","value":"<p>Missing Authentication for Critical Function (CWE-306) in the product cache revalidation Server Action (<code>src/app/actions.ts</code>, <code>revalidateProducts</code>) in MarcosCamara01 Ecommerce Template before commit <code>ec97209</code> allows a remote, unauthenticated attacker to force expiration of the entire storefront product cache at will. The file declares <code>\"use server\"</code> at file scope, so every exported function compiles into a POST-invokable Server Action; <code>revalidateProducts</code> calls <code>updateTag(\"products\")</code> with no session or role check, unlike the read-only actions in the same file which are safe by construction. Two client components under <code>src/components/admin</code> import the function, which causes its Server Action id to be compiled into a public <code>/_next/static</code> chunk that the application's admin middleware (<code>proxy.ts</code>) does not gate, so any unauthenticated user can extract that id from the public bundle and invoke the action directly. With <code>cacheComponents</code> enabled, the entire storefront (home, categories, product pages, search) is served from <code>\"use cache\"</code> entries produced by <code>getAllProducts</code>, <code>getCategoryProducts</code> and <code>getProduct</code>, all tagged <code>products</code> with an hours-long <code>cacheLife</code>. Repeated unauthenticated invocation of <code>revalidateProducts</code> keeps that cache permanently cold, forcing every visitor's request to read the full product catalog from Postgres instead of serving from cache, degrading storefront availability at near-zero attacker cost.</p>"}],"value":"Missing Authentication for Critical Function (CWE-306) in the product cache revalidation Server Action (src/app/actions.ts, revalidateProducts) in MarcosCamara01 Ecommerce Template before commit ec97209 allows a remote, unauthenticated attacker to force expiration of the entire storefront product cache at will. The file declares \"use server\" at file scope, so every exported function compiles into a POST-invokable Server Action; revalidateProducts calls updateTag(\"products\") with no session or role check, unlike the read-only actions in the same file which are safe by construction. Two client components under src/components/admin import the function, which causes its Server Action id to be compiled into a public /_next/static chunk that the application's admin middleware (proxy.ts) does not gate, so any unauthenticated user can extract that id from the public bundle and invoke the action directly. With cacheComponents enabled, the entire storefront (home, categories, product pages, search) is served from \"use cache\" entries produced by getAllProducts, getCategoryProducts and getProduct, all tagged products with an hours-long cacheLife. Repeated unauthenticated invocation of revalidateProducts keeps that cache permanently cold, forcing every visitor's request to read the full product catalog from Postgres instead of serving from cache, degrading storefront availability at near-zero attacker cost."}],"impacts":[{"capecId":"CAPEC-1","descriptions":[{"lang":"en","value":"CAPEC-1 Accessing Functionality Not Properly Constrained by ACLs"}]}],"metrics":[{"cvssV4_0":{"Automatable":"NOT_DEFINED","Recovery":"NOT_DEFINED","Safety":"NOT_DEFINED","attackComplexity":"LOW","attackRequirements":"NONE","attackVector":"NETWORK","baseScore":6.9,"baseSeverity":"MEDIUM","exploitMaturity":"NOT_DEFINED","privilegesRequired":"NONE","providerUrgency":"NOT_DEFINED","subAvailabilityImpact":"NONE","subConfidentialityImpact":"NONE","subIntegrityImpact":"NONE","userInteraction":"NONE","valueDensity":"NOT_DEFINED","vectorString":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N","version":"4.0","vulnAvailabilityImpact":"LOW","vulnConfidentialityImpact":"NONE","vulnIntegrityImpact":"NONE","vulnerabilityResponseEffort":"NOT_DEFINED"},"format":"CVSS","scenarios":[{"lang":"en","value":"GENERAL"}]}],"problemTypes":[{"descriptions":[{"cweId":"CWE-306","description":"CWE-306 Missing Authentication for Critical Function","lang":"en","type":"CWE"}]}],"providerMetadata":{"dateUpdated":"2026-09-28T15:29:03.261Z","orgId":"4daa8cea-433a-44bd-9456-53b127fc289a","shortName":"Secur0"},"references":[{"tags":["patch"],"url":"https://github.com/MarcosCamara01/ecommerce-template/commit/ec97209e6c7663cba7b5164468d6946cbfe2f19a"},{"tags":["third-party-advisory","technical-description"],"url":"https://secur0.com/en/cna/cve-list/cve-2026-91154-missing-authentication-ecommerce-template-cache-revalidation-dos"}],"solutions":[{"lang":"en","supportingMedia":[{"base64":false,"type":"text/html","value":"<p>Update to a build including commit <code>ec97209</code>, which moves <code>revalidateProducts</code> out of the file-scoped <code>\"use server\"</code> module into a server-only module and restricts its only network-reachable caller (<code>GET /api/cron/catalog-sync</code>) with an internal credential check. Do not export unauthenticated mutations from a file-scoped <code>\"use server\"</code> module; gate any cache-invalidation action behind an admin/session check or remove the client-callable export entirely.</p>"}],"value":"Update to a build including commit ec97209, which moves revalidateProducts out of the file-scoped \"use server\" module into a server-only module and restricts its only network-reachable caller (GET /api/cron/catalog-sync) with an internal credential check. Do not export unauthenticated mutations from a file-scoped \"use server\" module; gate any cache-invalidation action behind an admin/session check or remove the client-callable export entirely."}],"source":{"discovery":"EXTERNAL"},"tags":["x_open-source"],"title":"Missing authentication in Ecommerce Template product cache revalidation allows unauthenticated denial of service"}},"cveMetadata":{"assignerOrgId":"4daa8cea-433a-44bd-9456-53b127fc289a","assignerShortName":"Secur0","cveId":"CVE-2026-91154","datePublished":"2026-09-28T15:29:03.261Z","dateReserved":"2026-09-14T21:05:54.953Z","dateUpdated":"2026-09-28T17:52:40.759Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.2"},"nvd":{"publishedDate":"2026-09-28 16:17:17","lastModifiedDate":"2026-09-29 21:32:59","problem_types":["CWE-306","CWE-306 CWE-306 Missing Authentication for Critical Function"],"metrics":{"cvssMetricV40":[{"source":"4daa8cea-433a-44bd-9456-53b127fc289a","type":"Secondary","cvssData":{"version":"4.0","vectorString":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X","baseScore":6.9,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","attackRequirements":"NONE","privilegesRequired":"NONE","userInteraction":"NONE","vulnConfidentialityImpact":"NONE","vulnIntegrityImpact":"NONE","vulnAvailabilityImpact":"LOW","subConfidentialityImpact":"NONE","subIntegrityImpact":"NONE","subAvailabilityImpact":"NONE","exploitMaturity":"NOT_DEFINED","confidentialityRequirement":"NOT_DEFINED","integrityRequirement":"NOT_DEFINED","availabilityRequirement":"NOT_DEFINED","modifiedAttackVector":"NOT_DEFINED","modifiedAttackComplexity":"NOT_DEFINED","modifiedAttackRequirements":"NOT_DEFINED","modifiedPrivilegesRequired":"NOT_DEFINED","modifiedUserInteraction":"NOT_DEFINED","modifiedVulnConfidentialityImpact":"NOT_DEFINED","modifiedVulnIntegrityImpact":"NOT_DEFINED","modifiedVulnAvailabilityImpact":"NOT_DEFINED","modifiedSubConfidentialityImpact":"NOT_DEFINED","modifiedSubIntegrityImpact":"NOT_DEFINED","modifiedSubAvailabilityImpact":"NOT_DEFINED","Safety":"NOT_DEFINED","Automatable":"NOT_DEFINED","Recovery":"NOT_DEFINED","valueDensity":"NOT_DEFINED","vulnerabilityResponseEffort":"NOT_DEFINED","providerUrgency":"NOT_DEFINED"}}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-09-28T17:52:26.669048Z","id":"CVE-2026-91154","options":[{"exploitation":"none"},{"automatable":"yes"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"configurations":[]},"legacy_mitre":{"record":{"CveYear":"2026","CveId":"91154","Ordinal":"1","Title":"Missing authentication in Ecommerce Template product cache reval","CVE":"CVE-2026-91154","Year":"2026"},"notes":[{"CveYear":"2026","CveId":"91154","Ordinal":"1","NoteData":"Missing Authentication for Critical Function (CWE-306) in the product cache revalidation Server Action (src/app/actions.ts, revalidateProducts) in MarcosCamara01 Ecommerce Template before commit ec97209 allows a remote, unauthenticated attacker to force expiration of the entire storefront product cache at will. The file declares \"use server\" at file scope, so every exported function compiles into a POST-invokable Server Action; revalidateProducts calls updateTag(\"products\") with no session or role check, unlike the read-only actions in the same file which are safe by construction. Two client components under src/components/admin import the function, which causes its Server Action id to be compiled into a public /_next/static chunk that the application's admin middleware (proxy.ts) does not gate, so any unauthenticated user can extract that id from the public bundle and invoke the action directly. With cacheComponents enabled, the entire storefront (home, categories, product pages, search) is served from \"use cache\" entries produced by getAllProducts, getCategoryProducts and getProduct, all tagged products with an hours-long cacheLife. Repeated unauthenticated invocation of revalidateProducts keeps that cache permanently cold, forcing every visitor's request to read the full product catalog from Postgres instead of serving from cache, degrading storefront availability at near-zero attacker cost.","Type":"Description","Title":"Missing authentication in Ecommerce Template product cache reval"}]}}}