CVE-2026-103536
Received Received - Intake

Authentication Bypass in ZongXR Supermarket 1.0.0.0

Vulnerability report for CVE-2026-103536, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-01

Last updated on: 2026-10-01

Assigner: VulDB

Description

A vulnerability was identified in ZongXR Supermarket 1.0.0.0. Affected by this vulnerability is the function OrderController.addOrder of the file order/src/main/java/com/supermarket/order/controller/OrderController.java of the component save Endpoint. Such manipulation of the argument userId leads to missing authentication. The attack can be executed remotely. The exploit is publicly available and might be used. The project was informed of the problem early through an issue report but has not responded yet.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-01
Last Modified
2026-10-01
Generated
2026-10-01
AI Q&A
2026-10-01
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
zongxr supermarket 1.0.0.0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-287 When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.
CWE-306 The product does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is a missing authentication flaw in ZongXR Supermarket 1.0.0.0. The POST /order/manage/save endpoint allows unauthenticated attackers to inject arbitrary orders under any user's identity by supplying a victim's userId in the request. The endpoint accepts userId directly from the client without session or ticket validation, enabling 'ghost order' pollution in victims' order histories.

Detection Guidance

Check for unauthenticated POST requests to /order/manage/save endpoint with arbitrary userId parameters. Monitor for orders created without valid session tokens or authentication headers. Inspect gateway logs for external access to /order/** paths.

Impact Analysis

An attacker could inject fake orders under your name, polluting your order history and potentially disrupting auditing, accounting, and fulfillment workflows. The backend's money validation logic also uses the attacker-controlled userId, further compromising business logic and financial processes.

Mitigation Strategies

Immediately restrict access to /order/manage/save endpoint by adding it to authentication check lists in the gateway configuration. Validate userId ownership server-side before processing orders. Implement session or token validation for all order-related requests.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-103536. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart