CVE-2026-102293
Received Received - Intake

Improper Authorization in Tacomall Backend API

Vulnerability report for CVE-2026-102293, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-29

Last updated on: 2026-09-29

Assigner: VulDB

Description

A vulnerability was identified in realjerrytang tacomall 1.0.0. Impacted is the function OrgStaffServiceImpl.add of the file ApiMaApplication.java of the component api-admin Backend. The manipulation of the argument isAdmin/jobId leads to improper authorization. Remote exploitation of the attack is possible. The exploit is publicly available and might be used.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-29
Last Modified
2026-09-29
Generated
2026-09-29
AI Q&A
2026-09-29
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
realjerrytang tacomall 1.0.0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-266 A product incorrectly assigns a privilege to a particular actor, creating an unintended sphere of control for that actor.
CWE-285 The product does not perform or incorrectly performs an authorization check when an actor attempts to access a resource or perform an action.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability allows unauthenticated attackers to create administrator accounts in the Tacomall application due to improper authorization checks. The OrgStaffServiceImpl.add function in ApiMaApplication.java does not verify tokens or permissions, enabling attackers to set isAdmin=1 and create a superadmin account via a POST request to /orgStaff/add. The api-admin backend lacks authorization controls, allowing full platform access after login.

Detection Guidance

Check for unauthorized POST requests to /orgStaff/add or /api/ma endpoints. Monitor logs for admin account creation events without prior authentication. Inspect network traffic for JSON payloads containing isAdmin=1 or jobId manipulation.

Impact Analysis

An attacker could exploit this to gain full administrative control over the Tacomall platform. This includes creating admin accounts, modifying or deleting data, accessing sensitive information, and performing unauthorized actions without any prior authentication or credentials.

Compliance Impact

This vulnerability could lead to non-compliance with GDPR and HIPAA by enabling unauthorized access to sensitive personal or health data. It violates principles of least privilege, data integrity, and confidentiality, potentially resulting in legal penalties and reputational damage.

Mitigation Strategies

Apply input validation to OrgStaffServiceImpl.add to reject isAdmin and jobId fields. Add @SimpleRestLogin annotation to enforce token checks. Restrict access to /orgStaff/add and /api/ma endpoints. Update to patched versions if available.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-102293. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart