Threats Tagged 'cve-2026-91154'
View all threats tagged with 'cve-2026-91154'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'cve-2026-91154'
Click on any threat for detailed analysis and mitigation recommendations
CVE-2026-91154 is a vulnerability in the MarcosCamara01 Ecommerce Template allowing unauthenticated remote attackers to invoke a critical server action that forces expiration of the entire storefront product cache. The affected function, revalidateProducts, lacks authentication checks and is exposed publicly via compiled server action IDs accessible in a public static chunk. This enables attackers to repeatedly invalidate the cache, causing all product pages to bypass caching and query the database directly, degrading storefront availability. Join the discussion | GCVE Database | 09/28/2026, 18:31:24 UTC Added: 09/29/2026, 04:42:08 UTC |
0 Missing Authentication for Critical Function (CWE-306) in the product cache revalidation Server Action (src/app/actions.ts, revalidateProducts) in MarcosCamara01 Ecommerce Template before commit ec97209 allows a remote, unauthenticated attacker to force expiration of the entire storefront product cache at will. The file declares "use server" at file scope, so every exported function compiles into a POST-invokable Server Action; revalidateProducts calls updateTag("products") with no session or role check, unlike the read-only actions in the same file which are safe by construction. Two client components under src/components/admin import the function, which causes its Server Action id to be compiled into a public /_next/static chunk that the application's admin middleware (proxy.ts) does not gate, so any unauthenticated user can extract that id from the public bundle and invoke the action directly. With cacheComponents enabled, the entire storefront (home, categories, product pages, search) is served from "use cache" entries produced by getAllProducts, getCategoryProducts and getProduct, all tagged products with an hours-long cacheLife. Repeated unauthenticated invocation of revalidateProducts keeps that cache permanently cold, forcing every visitor's request to read the full product catalog from Postgres instead of serving from cache, degrading storefront availability at near-zero attacker cost. Join the discussion | CVE Database V5 | 09/28/2026, 15:29:03 UTC Added: 09/28/2026, 15:48:31 UTC |
Showing 1 to 2 of 2 results