Cyber & AI intelligence
Wasteland.
Briefs indexed2924
Issues30
Published Mondays07:30 CT
⚡ Active KEV CVE-2026-102361 2026-09-28

mall4j Password Update Flaw Lets Unauthenticated Attackers Take Over Any Storefront Account (CVE-2026-102361)

"CVE-2026-102361 is a critical missing-authentication vulnerability in mall4j through version 4.0. It lets unauthenticated attackers reset the password of any storefront account."

CVE-2026-102361 is a critical missing-authentication vulnerability in mall4j through version 4.0. It lets unauthenticated attackers reset the password of any storefront account.

What Is It

The bug is in the PUT /user/updatePwd endpoint of mall4j, an open-source e-commerce platform maintained by gz-yami. The endpoint never checks who is making the request. An attacker can put any target username in the request body and overwrite that account's password without verification.

It is classified as CWE-306 (Missing Authentication for Critical Function). VulnCheck, the CNA, disclosed it. The NVD record currently has a status of "Received." The references include a public proof-of-concept script titled A01_updatepwd_account_takeover.py. The advisory also links to the relevant code in UserRegisterController.java.

Why It Matters

According to the advisory, successful exploitation allows full account takeover and exposes customers' orders and personal data.

The attack works over the network, is low in complexity, and needs no privileges or user interaction. It has a high impact on both confidentiality and integrity. Because a public PoC is linked from the CVE record, the barrier to exploitation is low.

As of this writing, the vulnerability does not appear in the CISA Known Exploited Vulnerabilities (KEV) catalog. The supplied data does not confirm active exploitation in the wild.

What's Vulnerable

No CPE entries have been published in the NVD record yet.

Patch Status

The supplied NVD and advisory data do not reference a fixed version or vendor patch. Because the CVE has no KEV entry, no CISA-mandated remediation or due date applies. Organizations running mall4j 4.0 or earlier should:

Sources