Sceawere

Vulnerability Detail

CVE-2026-102364UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

mall4j Authentication Bypass Vulnerability

Vulnerability Metadata

Severity
Medium
Score / CVSS
5.4
Creation Date
7h ago
Vendor
gz-yami
Product
mall4j
Attack Type
Improper Authentication
Vector String
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N
Attack Complexity
LOW

Narrative and Response

Description

mall4j through 4.0 fails to validate the sysType field in sa-token sessions, allowing storefront customers to authenticate as back-office users by reusing their session tokens. Attackers can register on the public storefront and use their customer session token to access admin endpoints lacking @PreAuthorize permission checks, including menu listings, file uploads, and configuration endpoints.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "5.4",
  "pubDate": "2026-09-29T00:17:03.633Z",
  "pubdate": "2026-09-29T00:17:03.633Z",
  "executiveSummary": "The mall4j application, through version 4.0, exhibits a critical authentication bypass vulnerability due to inadequate validation of the sysType field within sa-token session objects. This flaw allows unprivileged storefront users to impersonate back-office administrative accounts by manipulating or reusing session tokens.\nThe vulnerability originates from a failure to verify the context of a session, effectively decoupling the user's privilege level from their assigned token. Attackers can leverage this by authenticating as standard customers on the public-facing storefront and subsequently accessing restricted administrative endpoints.\nThe impact includes unauthorized access to sensitive system functions, including configuration management, file uploads, and organizational menu structures. Because many administrative endpoints lack mandatory @PreAuthorize security annotations, the exploit allows for trivial privilege escalation. The risk is significant, as it grants unauthorized actors the ability to perform administrative actions, potentially leading to full system compromise or unauthorized data modification within the back-office environment.",
  "technicalDetails": "The vulnerability stems from improper session management within the mall4j integration of the sa-token framework. In the affected versions, the sysType parameter, which is intended to designate the authentication realm (e.g., storefront customer vs. administrative back-office), is not strictly validated during session access requests.\nThe exploitation flow begins with the attacker registering a legitimate account on the public storefront. Upon successful authentication, the application issues a session token managed by sa-token. Because the backend fails to verify the sysType claim associated with this token against the specific security requirements of the requested endpoint, the session token remains valid for restricted administrative resources.\nAttackers can bypass security controls by targeting administrative endpoints that lack explicit @PreAuthorize permission enforcement. Instead of relying on traditional role-based access control (RBAC), these endpoints implicitly trust any provided, valid session token. By presenting their storefront session token to these unprotected admin controllers, the attacker is granted the same privilege level as a system administrator.\nThe attack is characterized by the following steps: 1) Account Registration: The attacker establishes a low-privilege storefront identity. 2) Token Acquisition: The attacker obtains a valid session token via the standard customer login process. 3) Resource Enumeration: The attacker identifies administrative endpoints that lack granular @PreAuthorize checks. 4) Exploitation: The attacker transmits the storefront session token to targeted administrative URIs, such as those related to file uploads, configuration, or menu management. The backend application, failing to enforce a 'sysType' check, treats the request as if it originated from a back-office administrator.\nThe scope of this vulnerability covers versions of mall4j up to 4.0. The lack of validation implies that the session state management logic does not differentiate between various authentication realms. Consequently, any successfully authenticated user—regardless of their intended portal—can access administrative functionality that does not explicitly check for specific administrative roles or scopes at the method level. Post-exploitation impact includes, but is not limited to, arbitrary file uploads leading to potential Remote Code Execution (RCE), unauthorized configuration changes, and the exposure of internal system data."
}
CVE-2026-102364: mall4j Authentication Bypass Vulnerability (MEDIUM Severity, CVSS: 5.4) | Sceawere