CVE-2026-108691
Received
Received - Intake
Improper Authorization in mall4j Leading to Cart Item Deletion
Vulnerability report for CVE-2026-108691, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.
Publication date: 2026-10-11
Last updated on: 2026-10-11
Assigner: VulnCheck
Description
Description
mall4j through 4.0 contains an improper authorization vulnerability that allows authenticated storefront customers to delete other shoppers' cart items through an operator precedence error in the cleanExpiryProdList SQL statement. Attackers can send one DELETE request to /p/shopCart/cleanExpiryProdList to remove every user's cart entries for off-shelf products, which do not return when products are restocked.
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| gz-yami | mall4j | 0 |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-783 | The product uses an expression in which operator precedence causes incorrect logic to be used. |