Skip to main content

Threats Tagged 'cve-2026-91154'

View all threats tagged with 'cve-2026-91154'. Filter and sort to focus on specific types of threats.

Pro Console Lifetime

Stop chasing alerts. Route them.

Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.

Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)

View Plans & Pricing

API access activates after upgrading in Console -> Billing.

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now

Filter Threats

Narrow down the results by type, severity, or affected countries

Search threats by title, CVE ID, or description. Maximum 100 characters.
Active filters (1):Tag: cve-2026-91154

Threats Tagged 'cve-2026-91154'

Click on any threat for detailed analysis and mitigation recommendations

CVE-2026-91154 is a vulnerability in the MarcosCamara01 Ecommerce Template allowing unauthenticated remote attackers to invoke a critical server action that forces expiration of the entire storefront product cache. The affected function, revalidateProducts, lacks authentication checks and is exposed publicly via compiled server action IDs accessible in a public static chunk. This enables attackers to repeatedly invalidate the cache, causing all product pages to bypass caching and query the database directly, degrading storefront availability.

Join the discussion

Missing Authentication for Critical Function (CWE-306) in the product cache revalidation Server Action (src/app/actions.ts, revalidateProducts) in MarcosCamara01 Ecommerce Template before commit ec97209 allows a remote, unauthenticated attacker to force expiration of the entire storefront product cache at will. The file declares "use server" at file scope, so every exported function compiles into a POST-invokable Server Action; revalidateProducts calls updateTag("products") with no session or role check, unlike the read-only actions in the same file which are safe by construction. Two client components under src/components/admin import the function, which causes its Server Action id to be compiled into a public /_next/static chunk that the application's admin middleware (proxy.ts) does not gate, so any unauthenticated user can extract that id from the public bundle and invoke the action directly. With cacheComponents enabled, the entire storefront (home, categories, product pages, search) is served from "use cache" entries produced by getAllProducts, getCategoryProducts and getProduct, all tagged products with an hours-long cacheLife. Repeated unauthenticated invocation of revalidateProducts keeps that cache permanently cold, forcing every visitor's request to read the full product catalog from Postgres instead of serving from cache, degrading storefront availability at near-zero attacker cost.

Join the discussion

Showing 1 to 2 of 2 results

Filters:Tag: cve-2026-91154
Page 1 of 1
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses