---
id: CVE-2026-91154
title: >-
  Missing Authentication for Critical Function (CWE-306) in the product cache
  revalidation Server Action (src/app/actions.ts, revalidateProducts) in
  MarcosCamara01 Ecommerce Template before commit ec97209 allows a remote,
  unauthenticated a…
summary: >-
  Missing Authentication for Critical Function (CWE-306) in the product cache
  revalidation Server Action (src/app/actions.ts, revalidateProducts) in
  MarcosCamara01 Ecommerce Template before commit ec97209 allows a remote,
  unauthenticated a…
severity: medium
cvss: 6.9
cvssVector: 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N'
cwe:
  - CWE-306
vendor: MarcosCamara01
product: Ecommerce Template
affected:
  - ecommerce_template < ec97209
published: '2026-09-28'
updated: '2026-09-28'
sourceUpdated: '2026-09-28T16:17:17.110'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-91154'
references:
  - url: >-
      https://github.com/MarcosCamara01/ecommerce-template/commit/ec97209e6c7663cba7b5164468d6946cbfe2f19a
    label: 4daa8cea-433a-44bd-9456-53b127fc289a
  - url: >-
      https://secur0.com/en/cna/cve-list/cve-2026-91154-missing-authentication-ecommerce-template-cache-revalidation-dos
    label: 4daa8cea-433a-44bd-9456-53b127fc289a
tags:
  - nvd
  - cve.org
cvssSource: cna
ingestedAt: '2026-09-28T16:15:01.374Z'
---

## Overview

Missing Authentication for Critical Function (CWE-306) in the product cache revalidation Server Action (src/app/actions.ts, revalidateProducts) in MarcosCamara01 Ecommerce Template before commit ec97209 allows a remote, unauthenticated attacker to force expiration of the entire storefront product cache at will. The file declares "use server" at file scope, so every exported function compiles into a POST-invokable Server Action; revalidateProducts calls updateTag("products") with no session or role check, unlike the read-only actions in the same file which are safe by construction. Two client components under src/components/admin import the function, which causes its Server Action id to be compiled into a public /_next/static chunk that the application's admin middleware (proxy.ts) does not gate, so any unauthenticated user can extract that id from the public bundle and invoke the action directly. With cacheComponents enabled, the entire storefront (home, categories, product pages, search) is served from "use cache" entries produced by getAllProducts, getCategoryProducts and getProduct, all tagged products with an hours-long cacheLife. Repeated unauthenticated invocation of revalidateProducts keeps that cache permanently cold, forcing every visitor's request to read the full product catalog from Postgres instead of serving from cache, degrading storefront availability at near-zero attacker cost.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
