CVE-2026-102361 is a critical missing-authentication vulnerability in mall4j through version 4.0. It lets unauthenticated attackers reset the password of any storefront account.
What Is It
The bug is in the PUT /user/updatePwd endpoint of mall4j, an open-source e-commerce platform maintained by gz-yami. The endpoint never checks who is making the request. An attacker can put any target username in the request body and overwrite that account's password without verification.
It is classified as CWE-306 (Missing Authentication for Critical Function). VulnCheck, the CNA, disclosed it. The NVD record currently has a status of "Received." The references include a public proof-of-concept script titled A01_updatepwd_account_takeover.py. The advisory also links to the relevant code in UserRegisterController.java.
Why It Matters
According to the advisory, successful exploitation allows full account takeover and exposes customers' orders and personal data.
- CVSS 3.1: 9.1 CRITICAL (
AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N) - CVSS 4.0: 9.3 CRITICAL
The attack works over the network, is low in complexity, and needs no privileges or user interaction. It has a high impact on both confidentiality and integrity. Because a public PoC is linked from the CVE record, the barrier to exploitation is low.
As of this writing, the vulnerability does not appear in the CISA Known Exploited Vulnerabilities (KEV) catalog. The supplied data does not confirm active exploitation in the wild.
What's Vulnerable
- Vendor: gz-yami
- Product: mall4j
- Affected versions: all versions through 4.0 (
<= 4.0) - Component:
PUT /user/updatePwdin the storefront API (yami-shop-api)
No CPE entries have been published in the NVD record yet.
Patch Status
The supplied NVD and advisory data do not reference a fixed version or vendor patch. Because the CVE has no KEV entry, no CISA-mandated remediation or due date applies. Organizations running mall4j 4.0 or earlier should:
- Watch the vendor repository and the VulnCheck advisory for a fix.
- Treat any internet-exposed storefront as at risk.
- Consider restricting access to the affected endpoint until a patch is available.