Description
mall4j through 4.0 contains a missing authentication vulnerability in the PUT /user/updatePwd endpoint that allows unauthenticated attackers to reset any storefront account password. Attackers can supply a target username in the request body to overwrite passwords without verification, enabling account takeover and access to orders and personal data.
Published: 2026-09-28
Score: 9.3 Critical
EPSS: n/a
KEV: No
Impact: Account Takeover
Action: Patch Immediately
AI Analysis

Impact

The vulnerability is a missing authentication in the PUT /user/updatePwd endpoint; attackers can supply a target username in the request body and reset passwords without verification. This allows account takeover, providing attackers with access to orders, personal data, and other sensitive information. The weakness corresponds to CWE-306.

Affected Systems

The affected product is GZ‑Yami’s mall4j, versions 4.0 and earlier. Any installation that has not applied updates to add authentication to the password update endpoint is vulnerable. The vulnerability is listed for all mall4j releases up to 4.0; later versions are not known to be affected.

Risk and Exploitability

The CVSS score of 9.3 indicates a high severity. The vulnerability is exploitable over the network by any unauthenticated user; no credentials or elevated privileges are required. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog. Attackers can target storefront accounts via a simple HTTP PUT request, leading to full account takeover. The risk remains significant until a patch is applied, and vigilance is recommended.

Generated by OpenCVE AI on September 29, 2026 at 00:24 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update to a mall4j version that secures the /user/updatePwd endpoint with proper authentication (e.g., the latest release).
  • If a patch is not yet available, block unauthenticated access to the updatePwd endpoint at the load balancer or firewall level (or remove the endpoint) until the fix is applied.
  • Enforce strict authentication or re‑authentication before processing any password change requests to eliminate the CWE-306 flaw.
  • Implement monitoring of password reset traffic and set up alerts for anomalous or excessive requests.

Generated by OpenCVE AI on September 29, 2026 at 00:24 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 28 Sep 2026 23:45:00 +0000

Type Values Removed Values Added
Description mall4j through 4.0 contains a missing authentication vulnerability in the PUT /user/updatePwd endpoint that allows unauthenticated attackers to reset any storefront account password. Attackers can supply a target username in the request body to overwrite passwords without verification, enabling account takeover and access to orders and personal data.
Title mall4j through 4.0 Missing Authentication in Password Update Endpoint
Weaknesses CWE-306
References
Metrics cvssV3_1

{'score': 9.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N'}

cvssV4_0

{'score': 9.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-09-28T23:34:27.140Z

Reserved: 2026-09-28T22:50:08.550Z

Link: CVE-2026-102361

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-29T00:17:03.183

Modified: 2026-09-29T00:17:03.183

Link: CVE-2026-102361

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-29T00:30:08Z

Weaknesses
  • CWE-306

    Missing Authentication for Critical Function