Sceawere
Vulnerability Detail
CVE-2026-102363UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
Missing Authentication in mall4j
Vulnerability Metadata
- Severity
- Low
- Score / CVSS
- 3.7
- Creation Date
- 7h ago
- Vendor
- gz-yami
- Product
- mall4j
- Attack Type
- Missing Authentication for Critical Function
- Vector String
- CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N
- Attack Complexity
- HIGH
Narrative and Response
Description
mall4j through 4.0 contains a missing authentication vulnerability in the DeliveryController checkDelivery endpoint that allows unauthenticated attackers to read shipment tracking information by supplying an order number parameter. Attackers can access carrier names, waybill numbers, and complete logistics trails for any order without authentication or ownership verification.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "3.7",
"pubDate": "2026-09-29T00:17:03.483Z",
"pubdate": "2026-09-29T00:17:03.483Z",
"executiveSummary": "The mall4j application, specifically through version 4.0, is affected by a critical missing authentication vulnerability within the DeliveryController component.\nThis security flaw allows unauthenticated remote attackers to bypass access control mechanisms and retrieve sensitive shipment tracking information, including carrier names, waybill numbers, and comprehensive logistics history.\nThe vulnerability originates from the improper implementation of authorization checks on the checkDelivery endpoint, which fails to validate the identity or session state of the requesting user.\nBy supplying a target order number parameter, an unauthorized actor can gain access to private data associated with any shipment within the system.\nThe impact includes the exposure of PII (Personally Identifiable Information) and logistics intelligence, which can be harvested at scale due to the lack of rate limiting or authentication requirements.\nThe vulnerability poses significant privacy risks and potential for data exfiltration, as the flaw resides at the application logic layer and can be exploited over the network without requiring prior system privileges or established user credentials.",
"technicalDetails": "The vulnerability is localized within the DeliveryController class of the mall4j framework, specifically affecting the checkDelivery endpoint. Analysis reveals that the application logic fails to perform a verification check for the requester's authentication token or ownership permissions prior to processing the incoming request.\nThe root cause is a failure to implement a secure access control decorator or interceptor on the public-facing API controller method. Consequently, the application processes the order number parameter supplied in the GET request without verifying if the requesting principal has authorization to view the requested resource.\nThe attack flow begins when an attacker identifies the endpoint associated with delivery tracking. By issuing an HTTP GET request to the checkDelivery endpoint and appending a valid order number as a URL parameter, the attacker forces the application to query the backend database for the associated logistics record. Because the application logic does not validate the session object, it returns the serialized logistics object—containing carrier details, waybill numbers, and detailed event logs—directly to the attacker in the response body.\nThe exploit requires no specific privileges and can be executed over the network without user interaction. The attack is trivial to automate; since the order number format is often predictable (e.g., sequential integers or common alphanumeric strings), an attacker can perform enumeration or bulk harvesting of logistics data by cycling through known or guessed order numbers.\nThere are no requirements for valid session tokens, cookies, or specific header configurations. The endpoint functions as an open information disclosure vector, effectively bypassing the security boundary intended to protect private user data. The impact extends beyond simple logistics exposure, as the inclusion of full logistics trails allows for the reconstruction of delivery addresses and user movement patterns, facilitating further social engineering or privacy-invasive activities against the affected users. The vulnerability exists across all versions of mall4j up to and including 4.0."
}