Track vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
9.1

CVE-2026-102361: mall4j allows anyone to change a user’s password

CVE-2026-102361 · published 3 days ago
Summary

The mall4j software (up to version 4.0) lets anyone send a request to change a user’s password without first confirming they are the account owner. This means an attacker could reset passwords for any shopper, take over accounts, and see order history or personal information. Apply the vendor’s update or patch that adds proper login checks to the password‑change function.

What to do

The CVE record does not list a fixed version. Check the vendor's site or the advisory links below - a fix may already be released.

Affected software
VendorProductAffected versions
gz-yami mall4j <= 4.0
Original advisory text
mall4j through 4.0 Missing Authentication in Password Update Endpoint
mall4j through 4.0 contains a missing authentication vulnerability in the PUT /user/updatePwd endpoint that allows unauthenticated attackers to reset any storefront account password. Attackers can supply a target username in the request body to overwrite passwords without verification, enabling account takeover and access to orders and personal data.
Fix within
Internet-facing 3 days
Internal 60 days
  • Not known to be exploited
  • Can be exploited automatically
  • Gives an attacker full control
Severity
9.1 Critical
Exploitation
<1% chance of attack within 30 days
Type
CWE-306Missing Authentication for Critical Function
Timeline
Published28 Sep 2026
Updated2 Oct 2026
First seen29 Sep 2026
Sources
CVE-2026-102361 · MITRE
Track software like this
Free during beta