Description
mall4j through 4.0 contains a missing authentication vulnerability in the DeliveryController checkDelivery endpoint that allows unauthenticated attackers to read shipment tracking information by supplying an order number parameter. Attackers can access carrier names, waybill numbers, and complete logistics trails for any order without authentication or ownership verification.
Published: 2026-09-28
Score: 6.3 Medium
EPSS: n/a
KEV: No
Impact: Information disclosure of shipment tracking data
Action: Apply Patch
AI Analysis

Impact

Mall4j through version 4.0 is missing authentication in the DeliveryController checkDelivery endpoint, allowing attackers to supply an order number and obtain full shipment tracking details. The disclosed information includes carrier names, waybill numbers and the complete logistics trail for any order. This represents a confidentiality breach as no identity or ownership verification is performed before data is returned, exposing sensitive logistical information to unauthenticated users.

Affected Systems

The vulnerability affects the Mall4j application developed by gz‑yami, impacting all releases up to and including version 4.0. Any deployment of these versions that exposes the DeliveryController checkDelivery endpoint to external clients is susceptible.

Risk and Exploitability

The CVSS score of 6.3 classifies the issue as moderate. EPSS information is not available, indicating that the current data does not provide a clear estimate of exploitation likelihood, but the vulnerability can be exploited remotely over the web interface without any credentials. The vulnerability is not listed in CISA’s KEV catalog. Attackers can obtain shipping details for any order simply by sending a request with an order number, making it trivial for malicious actors to gather potentially sensitive logistics data.

Generated by OpenCVE AI on September 29, 2026 at 00:23 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Contact gz-yami to obtain a patched release of Mall4j or an official update that enforces authentication for the DeliveryController checkDelivery endpoint.
  • If a patch is not yet available, restrict access to the checkDelivery endpoint by enforcing authentication, rate limiting, or IP whitelisting so that only authorized staff can retrieve shipment information.
  • Review the source code for the DeliveryController implementation to add proper ownership verification or session checks, ensuring that only the order owner or privileged roles can access tracking data.

Generated by OpenCVE AI on September 29, 2026 at 00:23 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 28 Sep 2026 23:45:00 +0000

Type Values Removed Values Added
Description mall4j through 4.0 contains a missing authentication vulnerability in the DeliveryController checkDelivery endpoint that allows unauthenticated attackers to read shipment tracking information by supplying an order number parameter. Attackers can access carrier names, waybill numbers, and complete logistics trails for any order without authentication or ownership verification.
Title mall4j through 4.0 Unauthenticated Shipment Tracking Disclosure via Order Number
Weaknesses CWE-306
References
Metrics cvssV3_1

{'score': 3.7, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N'}

cvssV4_0

{'score': 6.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-09-28T23:34:28.513Z

Reserved: 2026-09-28T22:50:18.857Z

Link: CVE-2026-102363

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-29T00:17:03.483

Modified: 2026-09-29T00:17:03.483

Link: CVE-2026-102363

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-29T00:30:08Z

Weaknesses
  • CWE-306

    Missing Authentication for Critical Function