Description
mall4j through 4.0 fails to validate the sysType field in sa-token sessions, allowing storefront customers to authenticate as back-office users by reusing their session tokens. Attackers can register on the public storefront and use their customer session token to access admin endpoints lacking @PreAuthorize permission checks, including menu listings, file uploads, and configuration endpoints.
Published: 2026-09-28
Score: 5.3 Medium
EPSS: n/a
KEV: No
Impact: Unauthorized Administrative Access
Action: Apply Patch
AI Analysis

Impact

Mall4j versions up to 4.0 do not validate the sysType field within sa-token sessions, which allows a storefront customer to reuse their session token as a back‑office user. The flaw permits attackers to register a normal storefront account and then use that session token to authenticate against the admin API, bypassing authorization checks. As a result, attackers can retrieve confidential system menus, upload arbitrary files, and modify configuration endpoints that are intended for administrators only.

Affected Systems

The vulnerability affects the gz‑yami Mall4j e‑commerce platform, specifically all releases through version 4.0. No other vendors or products are listed as affected by this issue.

Risk and Exploitability

The CVSS score of 5.3 indicates a medium level of severity, while the EPSS score is not available. The flaw is not listed in the CISA KEV catalog. Attackers need only access the public storefront to register an account; no special privileges or network access beyond the ordinary electorate are required. The exploit path is straightforward: acquire a valid storefront token, then send requests to admin URLs that lack further permission checks. Because the flaw requires no code execution, the risk is primarily confined to misappropriation of administrative functions and potential data exposure.

Generated by OpenCVE AI on September 29, 2026 at 00:22 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Mall4j to a version where sysType token validation is enforced
  • Modify the authentication filter to reject admin API requests that carry non‑admin session tokens
  • Ensure all admin endpoints are annotated with @PreAuthorize or an equivalent role check
  • Restrict admin API traffic to internal or trusted networks only

Generated by OpenCVE AI on September 29, 2026 at 00:22 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 28 Sep 2026 23:45:00 +0000

Type Values Removed Values Added
Description mall4j through 4.0 fails to validate the sysType field in sa-token sessions, allowing storefront customers to authenticate as back-office users by reusing their session tokens. Attackers can register on the public storefront and use their customer session token to access admin endpoints lacking @PreAuthorize permission checks, including menu listings, file uploads, and configuration endpoints.
Title mall4j through 4.0 Improper Authentication Accepts Storefront Tokens on Admin API
Weaknesses CWE-287
References
Metrics cvssV3_1

{'score': 5.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N'}

cvssV4_0

{'score': 5.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-09-28T23:34:29.221Z

Reserved: 2026-09-28T22:50:19.220Z

Link: CVE-2026-102364

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-29T00:17:03.633

Modified: 2026-09-29T00:17:03.633

Link: CVE-2026-102364

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-29T00:30:08Z

Weaknesses