CVE-2026-102363
Received Received - Intake

Unauthenticated Shipment Tracking Access in mall4j

Vulnerability report for CVE-2026-102363, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-29

Last updated on: 2026-09-29

Assigner: VulnCheck

Description

mall4j through 4.0 contains a missing authentication vulnerability in the DeliveryController checkDelivery endpoint that allows unauthenticated attackers to read shipment tracking information by supplying an order number parameter. Attackers can access carrier names, waybill numbers, and complete logistics trails for any order without authentication or ownership verification.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-29
Last Modified
2026-09-29
Generated
2026-09-29
AI Q&A
2026-09-29
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Currently, no data is known.

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-306 The product does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is a missing authentication flaw in the mall4j e-commerce platform through version 4.0. It allows unauthenticated attackers to access shipment tracking information by providing an order number to the DeliveryController checkDelivery endpoint. Attackers can view carrier names, waybill numbers, and full logistics trails without authentication or ownership verification.

Detection Guidance

To detect this vulnerability, check if the /delivery/check endpoint is accessible without authentication. Use curl to send a GET request with a test order number: curl -v http://<target>/delivery/check?orderNumber=12345. If the response includes shipment details without requiring login, the system is vulnerable.

Impact Analysis

Unauthenticated attackers can access sensitive shipping details of any order by knowing the order number. This includes carrier names, waybill numbers, and logistics trails, enabling unauthorized tracking of shipments. Attackers could use this to monitor deliveries, potentially leading to theft or privacy violations.

Compliance Impact

This vulnerability likely violates GDPR due to unauthorized access to personal data (shipping details) and HIPAA if healthcare-related shipments are involved. It exposes customer information without consent, leading to potential non-compliance with data protection requirements.

Mitigation Strategies

Immediately restrict access to the /delivery/check endpoint by updating Spring Security configurations to require authentication. Apply the latest mall4j patch or upgrade to a version beyond 4.0. Temporarily block unauthenticated requests to this endpoint via firewall rules until patched.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-102363. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart