CVE-2026-108691
Received Received - Intake

Improper Authorization in mall4j Leading to Cart Item Deletion

Vulnerability report for CVE-2026-108691, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-11

Last updated on: 2026-10-11

Assigner: VulnCheck

Description

mall4j through 4.0 contains an improper authorization vulnerability that allows authenticated storefront customers to delete other shoppers' cart items through an operator precedence error in the cleanExpiryProdList SQL statement. Attackers can send one DELETE request to /p/shopCart/cleanExpiryProdList to remove every user's cart entries for off-shelf products, which do not return when products are restocked.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-11
Last Modified
2026-10-11
Generated
2026-10-11
AI Q&A
2026-10-11
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
gz-yami mall4j 0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-783 The product uses an expression in which operator precedence causes incorrect logic to be used.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

CVE-2026-108691 is an improper authorization vulnerability in the mall4j e-commerce platform (versions through 4.0). It allows authenticated storefront customers to delete other users' shopping cart items due to an operator precedence error in the SQL statement used by the cleanExpiryProdList endpoint. The flaw enables a single DELETE request to /p/shopCart/cleanExpiryProdList to remove all cart entries for products marked as off-shelf, even if those products are later restocked.

Detection Guidance

To detect this vulnerability, monitor HTTP DELETE requests to the endpoint /p/shopCart/cleanExpiryProdList. Check for requests from authenticated users that result in deletion of cart items not belonging to them. Review application logs for unusual deletion patterns or unauthorized access to other users' cart data.

Impact Analysis

This vulnerability can lead to irreversible data loss for affected users. Attackers with an authenticated session can delete items from other users' carts, potentially causing inconvenience or financial loss if critical items are removed. The impact includes disruption of shopping experiences and potential loss of trust in the platform.

Compliance Impact

This vulnerability could potentially violate GDPR's data integrity and availability principles by allowing unauthorized deletion of user cart data, which may include personal or sensitive information. It also risks non-compliance with HIPAA if the e-commerce system handles protected health information, as unauthorized data alteration or deletion could compromise patient confidentiality.

Mitigation Strategies

Immediately patch mall4j to a version beyond 4.0. Implement strict input validation for the cleanExpiryProdList endpoint. Ensure SQL queries use explicit parentheses to enforce correct operator precedence. Restrict DELETE operations to only the authenticated user's own cart items.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-108691. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart