Sceawere
Vulnerability Detail
CVE-2026-102361UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
mall4j Authentication Bypass Vulnerability
Vulnerability Metadata
- Severity
- Critical
- Score / CVSS
- 9.1
- Creation Date
- 7h ago
- Vendor
- gz-yami
- Product
- mall4j
- Attack Type
- Missing Authentication for Critical Function
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
- Attack Complexity
- LOW
Narrative and Response
Description
mall4j through 4.0 contains a missing authentication vulnerability in the PUT /user/updatePwd endpoint that allows unauthenticated attackers to reset any storefront account password. Attackers can supply a target username in the request body to overwrite passwords without verification, enabling account takeover and access to orders and personal data.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "9.1",
"pubDate": "2026-09-29T00:17:03.183Z",
"pubdate": "2026-09-29T00:17:03.183Z",
"executiveSummary": "The mall4j application, specifically through version 4.0, exhibits a critical authentication bypass vulnerability within the password reset functionality. This security flaw originates from a missing authentication check on the PUT /user/updatePwd endpoint, which serves as a significant security misconfiguration.\nThe vulnerability allows unauthenticated, remote attackers to perform unauthorized password resets for any storefront account. By manipulating the request body to specify a target username, an attacker can overwrite existing credentials without prior verification of identity or possession of the original password.\nThis represents a high-risk scenario leading to full account takeover, facilitating unauthorized access to sensitive user information, order history, and personal data. Because the exploit does not require prior authentication or elevated privileges, the barrier to entry for exploitation is low. The impact includes widespread compromise of user integrity and confidentiality, potentially leading to mass data exfiltration or fraudulent activity within the storefront environment.",
"technicalDetails": "The vulnerability resides in the implementation of the password update logic, specifically handled by the PUT /user/updatePwd endpoint. The root cause is a failure to enforce authentication filters or authorization checks on this controller before processing user-supplied input to alter account credentials.\nIn a secure implementation, an updatePwd operation must verify the request sender's session token or require the current password as an identity proof before allowing the modification of account credentials. In mall4j through 4.0, the application logic assumes that input received at this endpoint originates from a trusted source, failing to validate whether the requester owns the account identified by the username parameter.\nThe exploitation flow is straightforward and does not require complex reconnaissance. An attacker crafts a malicious HTTP PUT request directed at the /user/updatePwd endpoint. The request body must include the targeted account's username and the new password string desired by the attacker. Because the server-side code fails to perform a validation check for the session context, it processes the request directly.\nUpon receiving the request, the application retrieves the target user record from the backend database based on the provided username. It then performs an update operation, overwriting the existing hashed password stored in the user database with the hash of the attacker-supplied password. This operation does not verify the user's prior credentials or security tokens, effectively granting the attacker full control over the target account.\nThe vulnerability exposes the entire user base of the mall4j storefront to immediate account takeover. The network exposure is high, as the web application is typically internet-facing, allowing any remote actor to interact with the vulnerable endpoint. Post-exploitation impact is severe, as the attacker can authenticate as any victim, access PII, view sensitive order histories, and perform actions on behalf of the compromised user within the store's ecosystem. This lack of access control violates the core principles of identity management and session security."
}