Published: 2026-04-30
Last updated: 2026-04-30
Summary
Litium has identified and patched a security vulnerability in the Litium platform that, under specific conditions, could impact the security of user accounts on affected installations.
The vulnerability was discovered internally during routine security review. Litium has developed a fix and has deployed it across all affected versions. Litium has no indications of the vulnerability being utilized against any customer at this time.
Severity
Critical
Impact
If utilized, the vulnerability could impact the security of user accounts on an affected installation. Both storefront (end-customer) accounts and back office (administrative) accounts are within scope. The legitimate account owner would not receive an indication that the security of their account had been impacted, until attempting to log in and finding their credentials no longer working.
Due to the nature of the vulnerability, utilization cannot be reliably detected from server-side logs. Litium is therefore unable to confirm or rule out whether any specific installation has been impacted.
Scope
An installation is in scope if both of the following are true:
- The installation is running version 8.17 or later (see version table below for fixed versions per branch).
- The Storefront API is enabled on the installation. The Storefront API does not need to be in active use; being enabled is sufficient for the installation to be in scope.
Installations running versions earlier than 8.17, or installations on 8.17 or later where the Storefront API is not enabled, are not in scope.
Affected branches and fixed versions
|
Version
|
Fixed in version
|
|
8.17.0 - 8.17.5
|
8.17.6
|
|
8.18.0 - 8.18.6
|
8.18.7
|
|
8.19.0 - 8.19.3
|
8.19.4
|
|
8.20.0 - 8.20.3
|
8.20.4
|
|
8.21.0 - 8.21.2
|
8.21.3
|
|
8.22.0 - 8.22.2
|
8.22.3
|
|
8.23.0 - 8.23.4
|
8.23.5
|
|
8.24.0 - 8.24.1
|
8.24.2
|
|
8.25.0 - 8.25.3
|
8.25.4
|
|
8.26.0
|
8.26.1
|
|
8.27.0 - 8.27.1
|
8.27.2
|
|
8.28.0 - 8.28.2
|
8.28.3
|
|
8.29.0 - 8.29.1
|
8.29.2
|
|
8.30.0 - 8.30.3
|
8.30.4
|
Customer/partner action
Litium Serverless Cloud customers
No action required. Litium has deployed the fix to all affected installations on Litium Serverless Cloud. The fix has been applied by replacing the running version with a patched version of the same release; this is not a version upgrade. Affected Apps have been restarted to activate the fix.
In addition, Litium Serverless Cloud automatically protects future deployments and new releases. Versions affected by this vulnerability are detected during deployment and the fix is applied automatically. Installations on Litium Serverless Cloud cannot be deployed in a state where this vulnerability is present.
On-premises and self-hosted customers
Litium has prepared the fix for all supported branches, including legacy versions. To ensure the fix persists across deployments, on-premises and self-hosted customers should update to the patched version listed for their branch:
- Update to the fixed version listed above for their branch
- Redeploy and restart the affected application
- Verify the patched version is running
Note: Redeploying an unpatched version of the same release would result in the vulnerability being reintroduced. Updating to the patched version ensures the fix is permanent.
The fix is contained in a single component. The update is a low-risk in-place replacement followed by an application restart.
Mitigation
Litium has taken the following actions:
- Identified the vulnerability through internal security review
- Developed and tested a fix across all affected versions
- Deployed the fix to all affected installations on Litium Serverless Cloud
- Enabled automatic protection for future deployments and new releases on Litium Serverless Cloud
- Released patched versions for on-premises and self-hosted installations
- Reviewed available data for indications of utilization; none found
- Published this security update
Further information
The technical details of this vulnerability are not published in order to protect customers who have not yet applied the patch. Customers and partners with specific security or compliance questions can contact Litium support for further information. Litium has also created a FAQ regarding this vulnerability that can be found here: Litium Security FAQ 2026-04-30