CVE-2026-103538
Received Received - Intake

Authentication Bypass in ZongXR SuperMarket 1.0.0.0

Vulnerability report for CVE-2026-103538, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-01

Last updated on: 2026-10-01

Assigner: VulDB

Description

A security flaw has been discovered in ZongXR SuperMarket 1.0.0.0. Affected by this issue is the function OrderController.deleteOrder of the file order/src/main/java/com/supermarket/order/controller/OrderController.java of the component Order Deletion Endpoint. Performing a manipulation of the argument orderId results in missing authentication. The attack is possible to be carried out remotely. The exploit has been released to the public and may be used for attacks. The project was informed of the problem early through an issue report but has not responded yet.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-01
Last Modified
2026-10-01
Generated
2026-10-01
AI Q&A
2026-10-01
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
zongxr supermarket 1.0.0.0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-287 When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.
CWE-306 The product does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is a missing authentication flaw in ZongXR SuperMarket 1.0.0.0. The OrderController.deleteOrder function in order/src/main/java/com/supermarket/order/controller/OrderController.java allows remote attackers to delete orders by manipulating the orderId parameter without authentication. The attack is possible because the endpoint does not verify user identity or ownership of the order before deletion.

Detection Guidance

Check if the GET /order/manage/delete/{orderId} endpoint is accessible without authentication. Use tools like curl to send requests to this endpoint with arbitrary orderId values and verify if orders can be deleted without valid session tokens or user identity checks.

Impact Analysis

If you use ZongXR SuperMarket 1.0.0.0, an attacker could delete your orders remotely by knowing their IDs. This could lead to loss of order data, financial discrepancies, or disruption of service. The exploit is public, increasing the risk of attacks.

Compliance Impact

This vulnerability could violate GDPR's data integrity and availability principles by allowing unauthorized deletion of order data. For HIPAA, it may compromise protected health information if orders contain such data. Compliance requires ensuring data integrity and access controls, which this flaw undermines.

Mitigation Strategies

Immediately restrict access to the /order/** path in the gateway configuration to enforce authentication. Update the OrderController.deleteOrder function to validate user session and ownership before processing order deletion requests.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-103538. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart