Track vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
9.1
CVE-2026-102361: mall4j allows anyone to change a user’s password
CVE-2026-102361 · published 3 days ago
Summary
The mall4j software (up to version 4.0) lets anyone send a request to change a user’s password without first confirming they are the account owner. This means an attacker could reset passwords for any shopper, take over accounts, and see order history or personal information. Apply the vendor’s update or patch that adds proper login checks to the password‑change function.
What to do
The CVE record does not list a fixed version. Check the vendor's site or the advisory links below - a fix may already be released.
Affected software
| Vendor | Product | Affected versions |
|---|---|---|
| gz-yami | mall4j | <= 4.0 |
Original advisory text
mall4j through 4.0 Missing Authentication in Password Update Endpoint
mall4j through 4.0 contains a missing authentication vulnerability in the PUT /user/updatePwd endpoint that allows unauthenticated attackers to reset any storefront account password. Attackers can supply a target username in the request body to overwrite passwords without verification, enabling account takeover and access to orders and personal data.
References
- https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/102xxx/CVE-2026-1023... Vendor Advisory
- https://github.com/LinYuanyi1/cve-request-poc/blob/114b3f0d149e50a7678f591bf8043... Exploit
- https://github.com/gz-yami/mall4j Product
- https://github.com/gz-yami/mall4j/blob/ffc672fc1aa4320ce02d0b93853bb456ae0a4dae/... Third Party Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2026-102361 Vendor Advisory
- https://www.vulncheck.com/advisories/mall4j-through-4.0-missing-authentication-i... Vendor Advisory
Internet-facing
3 days
Internal
60 days
- Not known to be exploited
- Can be exploited automatically
- Gives an attacker full control
Type
CWE-306Missing Authentication for Critical Function
Timeline
Published28 Sep 2026
Updated2 Oct 2026
First seen29 Sep 2026
Track software like this
Free during beta