CVE-2026-103539
Received Received - Intake

Authentication Bypass in ZongXR SuperMarket via Username Manipulation

Vulnerability report for CVE-2026-103539, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-01

Last updated on: 2026-10-01

Assigner: VulDB

Description

A weakness has been identified in ZongXR SuperMarket 1.0.0.0. This affects the function startBuy of the file instant-buy/src/main/java/com/supermarket/instantbuy/controller/InstantBuyController.java of the component Instant Buy. Executing a manipulation of the argument Username can lead to missing authentication. The attack may be performed from remote. The exploit has been made available to the public and could be used for attacks. The project was informed of the problem early through an issue report but has not responded yet.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-01
Last Modified
2026-10-01
Generated
2026-10-01
AI Q&A
2026-10-01
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
zongxr supermarket 1.0.0.0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-287 When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.
CWE-306 The product does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is an access control weakness in ZongXR SuperMarket 1.0.0.0. It allows an authenticated attacker to manipulate the username parameter in the instant buy feature to create fake purchase records for other users. The system does not validate if the username in the request matches the authenticated user, enabling attackers to deplete inventory or block legitimate purchases for victims.

Detection Guidance

To detect this vulnerability, monitor network traffic for requests to the endpoint GET /instantbuy/manage/{itemId}/{userName} where the userName parameter does not match the authenticated user's identity. Check for unusual Redis key patterns or database records created under arbitrary usernames. Review logs for repeated 'Already purchased' errors from legitimate users.

Impact Analysis

If you use ZongXR SuperMarket, an attacker could manipulate your username to burn your one-time purchase eligibility, block your ability to buy items, or deplete inventory under your name. This could prevent you from purchasing desired items or cause financial losses if inventory is wasted.

Mitigation Strategies

Immediately restrict the GET /instantbuy/manage/{itemId}/{userName} endpoint to use only the authenticated user's username. Validate that the path parameter matches the authenticated user's identity before processing requests. Implement checks for duplicate purchases before inventory updates to prevent race conditions.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-103539. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart