CVE-2026-102365
Received Received - Intake

Unauthorized Address Data Exposure in mall4j

Vulnerability report for CVE-2026-102365, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-29

Last updated on: 2026-09-29

Assigner: VulnCheck

Description

mall4j through 4.0 fails to enforce authorization checks on GET endpoints in UserAddrController that retrieve customer address data. Authenticated attackers can call /user/addr/page and /user/addr/info endpoints to harvest all customer addresses including names, phone numbers, and postal information.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-29
Last Modified
2026-09-29
Generated
2026-09-29
AI Q&A
2026-09-29
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 2 associated CPEs
Vendor Product Version / Range
mall4j mall4j From 3.0 (inc) to 4.0 (inc)
yami mall4j to 4.0 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-862 The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

mall4j through version 4.0 has a missing authorization vulnerability in its admin user address endpoints. The GET endpoints /user/addr/page and /user/addr/info in UserAddrController fail to enforce proper access controls. Authenticated attackers can exploit this to retrieve all customer address data including names, phone numbers, and postal information without needing administrative privileges.

Detection Guidance

Check for unauthorized access to /user/addr/page and /user/addr/info endpoints. Monitor logs for repeated GET requests to these paths. Use tools like curl to test if these endpoints return sensitive data without proper authentication. Example: curl -X GET http://<target>/user/addr/page

Inspect UserAddrController.java for missing @PreAuthorize annotations on GET endpoints. Verify if admin and public APIs share the same authentication mechanism.

Impact Analysis

This vulnerability allows attackers to harvest sensitive personally identifiable information (PII) such as customer names, phone numbers, and postal addresses. The impact includes potential privacy violations, identity theft risks, and unauthorized access to confidential customer data stored in the system.

Compliance Impact

This vulnerability likely violates GDPR and HIPAA requirements for protecting personal data. GDPR mandates strict access controls for personal data, while HIPAA requires safeguards for protected health information. The unauthorized data exposure could result in regulatory penalties and legal consequences for non-compliance.

Mitigation Strategies

Apply strict authorization checks to /user/addr/page and /user/addr/info endpoints using @PreAuthorize. Ensure admin and public APIs use separate authentication mechanisms. Update to the latest version of mall4j if available.

Restrict access to admin API ports (e.g., 8085) and isolate Redis databases. Monitor for suspicious activity targeting these endpoints.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-102365. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart