Description
A vulnerability was identified in realjerrytang tacomall 1.0.0. Impacted is the function OrgStaffServiceImpl.add of the file ApiMaApplication.java of the component api-admin Backend. The manipulation of the argument isAdmin/jobId leads to improper authorization. Remote exploitation of the attack is possible. The exploit is publicly available and might be used.
Published: 2026-09-29
Score: 6.9 Medium
EPSS: n/a
KEV: No
Impact: Privilege Escalation / Unauthorized Access
Action: Immediate Patch
AI Analysis

Impact

The vulnerability arises from improper handling of the isAdmin/jobId arguments in OrgStaffServiceImpl.add within the api‑admin backend. This results in an authorization bypass that allows attackers to execute privileged functions without proper authentication, granting unauthorized access or privilege escalation. The weakness corresponds to CWE‑266 (Special‑Cased Authorization) and CWE‑285 (Improper Authorization) and could lead to unauthorized modification or disclosure of sensitive data.

Affected Systems

The affected product is realjerrytang tacomall, version 1.0.0. No additional versions are listed in the CVE data, so only this release is confirmed to have the flaw.

Risk and Exploitability

The CVSS score of 6.9 indicates a medium severity. No EPSS score is available, but the advisory notes that a public exploit is available and remote exploitation is possible. The flaw has not been listed in the CISA KEV catalog. Attackers could remotely exploit the vulnerability by manipulating the isAdmin and jobId parameters in HTTP requests, bypassing authorization checks.

Generated by OpenCVE AI on September 29, 2026 at 06:20 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply any vendor-released patch or upgrade to a fixed version of tacomall.
  • Restrict modification of the isAdmin and jobId parameters by enforcing strict input validation and proper role‑based access control in the API.
  • Monitor authentication and authorization logs for suspicious activity related to staff or job administration functions.

Generated by OpenCVE AI on September 29, 2026 at 06:20 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 29 Sep 2026 05:30:00 +0000

Type Values Removed Values Added
Description A vulnerability was identified in realjerrytang tacomall 1.0.0. Impacted is the function OrgStaffServiceImpl.add of the file ApiMaApplication.java of the component api-admin Backend. The manipulation of the argument isAdmin/jobId leads to improper authorization. Remote exploitation of the attack is possible. The exploit is publicly available and might be used.
Title realjerrytang tacomall api-admin Backend ApiMaApplication.java OrgStaffServiceImpl.add improper authorization
First Time appeared Realjerrytang
Realjerrytang tacomall
Weaknesses CWE-266
CWE-285
CPEs cpe:2.3:a:realjerrytang:tacomall:*:*:*:*:*:*:*:*
Vendors & Products Realjerrytang
Realjerrytang tacomall
References
Metrics cvssV2_0

{'score': 7.5, 'vector': 'AV:N/AC:L/Au:N/C:P/I:P/A:P/E:POC/RL:ND/RC:C'}

cvssV3_0

{'score': 7.3, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:C'}

cvssV3_1

{'score': 7.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:C'}

cvssV4_0

{'score': 6.9, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P'}


Subscriptions

Realjerrytang Tacomall
cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-09-29T05:15:10.156Z

Reserved: 2026-09-28T20:46:47.426Z

Link: CVE-2026-102293

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-29T06:16:58.543

Modified: 2026-09-29T06:16:58.543

Link: CVE-2026-102293

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-29T06:30:13Z

Weaknesses
  • CWE-266

    Incorrect Privilege Assignment

  • CWE-285

    Improper Authorization