CVE-2026-102364
Received Received - Intake

mall4j Session Token Authentication Bypass

Vulnerability report for CVE-2026-102364, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-29

Last updated on: 2026-09-29

Assigner: VulnCheck

Description

mall4j through 4.0 fails to validate the sysType field in sa-token sessions, allowing storefront customers to authenticate as back-office users by reusing their session tokens. Attackers can register on the public storefront and use their customer session token to access admin endpoints lacking @PreAuthorize permission checks, including menu listings, file uploads, and configuration endpoints.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-29
Last Modified
2026-09-29
Generated
2026-09-29
AI Q&A
2026-09-29
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 2 associated CPEs
Vendor Product Version / Range
gz-yami mall4j From 4.0 (inc)
gz-yami yami-shop From 4.0 (inc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-287 When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability affects mall4j versions through 4.0 due to improper validation of the sysType field in sa-token sessions. Storefront customers can authenticate as back-office users by reusing their session tokens. Attackers register on the public storefront and use their customer token to access admin endpoints that lack proper permission checks, such as menu listings, file uploads, and configuration endpoints.

Detection Guidance

To detect this vulnerability, check if your mall4j system allows storefront session tokens to access admin endpoints. Use the provided Python scripts to test endpoints like GET /sys/menu/table, GET /sys/menu/list, GET /sys/menu/listRootMenu, and GET /sys/menu/listChildrenMenu. If these return admin data without proper authorization, the system is vulnerable.

Impact Analysis

An attacker could gain unauthorized access to administrative functions, view sensitive data like permission maps or configurations, and potentially modify settings or upload malicious files. This could lead to data breaches, system compromise, or unauthorized changes to the application.

Compliance Impact

This vulnerability could lead to unauthorized access to sensitive data, violating GDPR's data protection principles and HIPAA's access controls. It may result in non-compliance due to potential data breaches, unauthorized data exposure, or insufficient access controls for protected health or personal information.

Mitigation Strategies

Immediately update mall4j to a version beyond 4.0. Ensure all admin endpoints have proper @PreAuthorize permission checks. Verify that the sysType field in sa-token sessions is validated correctly. Restrict access to Redis databases shared between admin and storefront applications.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-102364. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart