CVE-2026-108690
Received Received - Intake

Information Disclosure in mall4j Shopping Cart

Vulnerability report for CVE-2026-108690, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-11

Last updated on: 2026-10-11

Assigner: VulnCheck

Description

mall4j through 4.0 contains an information disclosure vulnerability that allows authenticated customers to read other shoppers' cart items due to an operator precedence error in the getShopCartExpiryItems SQL filter. Attackers with any storefront account can request GET /p/shopCart/expiryProdList to retrieve off-shelf product basket entries including product, SKU, quantity, shop, and promoter card numbers.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-11
Last Modified
2026-10-11
Generated
2026-10-11
AI Q&A
2026-10-11
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
gz-yami mall4j 0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-783 The product uses an expression in which operator precedence causes incorrect logic to be used.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

CVE-2026-108690 is an information disclosure vulnerability in mall4j through version 4.0. It allows authenticated users to read other customers' shopping cart items due to an operator precedence error in the SQL filter for the getShopCartExpiryItems function. Attackers can send a GET request to /p/shopCart/expiryProdList to retrieve off-shelf product basket entries, including product details, SKUs, quantities, shop information, and promoter card numbers.

Detection Guidance

To detect this vulnerability, check if the endpoint GET /p/shopCart/expiryProdList returns cart data belonging to other users. Use a script to send authenticated requests and compare returned cart IDs with the authenticated user's own basket IDs. Look for exposure of product, SKU, quantity, shop, and promoter card numbers in responses.

Impact Analysis

This vulnerability allows attackers with a valid storefront account to access sensitive cart data of other users. Exposed information includes product details, quantities, shop data, and promoter card numbers, which could lead to privacy violations, data leaks, or potential misuse of payment-related information.

Compliance Impact

This vulnerability likely violates GDPR due to unauthorized access to personal data and insufficient protection of user information. It may also conflict with HIPAA if promoter card numbers or other sensitive data are considered protected health information, though HIPAA primarily applies to healthcare entities.

Mitigation Strategies

Immediately update mall4j to a patched version beyond 4.0. If an update is unavailable, restrict access to the /p/shopCart/expiryProdList endpoint to authenticated users only and review SQL query logic in BasketMapper.xml to ensure proper operator precedence in the getShopCartExpiryItems filter.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-108690. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart