CVE-2026-102361
Received Received - Intake

Authentication Bypass in mall4j Allows Password Reset

Vulnerability report for CVE-2026-102361, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-29

Last updated on: 2026-09-29

Assigner: VulnCheck

Description

mall4j through 4.0 contains a missing authentication vulnerability in the PUT /user/updatePwd endpoint that allows unauthenticated attackers to reset any storefront account password. Attackers can supply a target username in the request body to overwrite passwords without verification, enabling account takeover and access to orders and personal data.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-29
Last Modified
2026-09-29
Generated
2026-09-29
AI Q&A
2026-09-29
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Currently, no data is known.

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-306 The product does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

CVE-2026-102361 is a missing authentication vulnerability in mall4j through version 4.0. It affects the PUT /user/updatePwd endpoint, allowing unauthenticated attackers to reset any storefront account password by providing a target username in the request body. No verification is required, enabling full account takeover and access to sensitive data like orders and personal information.

Detection Guidance

Check if the PUT /user/updatePwd endpoint is accessible without authentication. Use tools like curl to send a test request: curl -X PUT http://target/system/user/updatePwd -H 'Content-Type: application/json' -d '{"nickname":"target_user","password":"new_password"}'. If the request succeeds without authentication, the vulnerability exists.

Impact Analysis

This vulnerability allows attackers to take over any user account by resetting passwords without authentication. Impact includes unauthorized access to personal data, order history, and potentially financial information. Attackers could impersonate users, make purchases, or exfiltrate sensitive data stored in the system.

Compliance Impact

This vulnerability likely violates GDPR's data protection requirements by enabling unauthorized access to personal data. It may also breach HIPAA if the system handles protected health information. Organizations using mall4j could face compliance violations, legal penalties, and reputational damage due to unauthorized data exposure.

Mitigation Strategies

Immediately update mall4j to a patched version beyond 4.0. If an update is unavailable, restrict access to the /user/updatePwd endpoint using network-level controls or application firewalls. Implement authentication checks and require current password verification for password updates.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-102361. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart