Description
A vulnerability was detected in linlinjava litemall up to 1.8.0. This affects an unknown part of the file litemall-admin-api/src/main/java/org/linlinjava/litemall/admin/web/AdminAuthController.java of the component Login Endpoint. The manipulation results in improper restriction of excessive authentication attempts. The attack may be performed from remote. A high complexity level is associated with this attack. It is indicated that the exploitability is difficult. The exploit is now public and may be used. The project was informed of the problem early through an issue report but has not responded yet.
Published: 2026-10-05
Score: 6.3 Medium
EPSS: n/a
KEV: No
Impact: Authentication Bypass via uncontrolled login attempts
Action: Immediate Patch
AI Analysis

Impact

The vulnerability in linlinjava litemall arises from inadequate limitation of authentication attempts within the Login Endpoint AdminAuthController. This flaw allows an attacker to repeatedly submit credentials without restriction, increasing the probability of successfully guessing valid credentials. The weakness is identified as CWE-307 and CWE-799, corresponding to insufficient authentication and improper access control. Although no remote code execution is possible, an attacker who can repeatedly attempt logins may compromise user accounts and gain unauthorized administrative access, affecting confidentiality and integrity of the system.

Affected Systems

All installations of linlinjava litemall up to version 1.8.0 are affected. The attack vector is remote, targeting the exposed login API endpoint of the AdminAuthController. Vendors should verify which patch versions include a fix; the issue is reported but no response has yet been provided.

Risk and Exploitability

The CVSS score of 6.3 indicates moderate severity. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog. The exploitability is described as high complexity and difficult, yet the exploit is now public. Based on the description, it is inferred that an attacker from a remote location can exploit this weakness by performing continuous authentication attempts, potentially leading to account compromise if no lockout or rate‑limiting controls are in place.

Generated by OpenCVE AI on October 5, 2026 at 07:22 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the latest litemall release that addresses the authentication limitation issue
  • Configure an account lockout or rate‑limiting policy on the login endpoint to limit repeated attempts
  • Regularly review authentication logs and enforce multi‑factor authentication for administrative accounts

Generated by OpenCVE AI on October 5, 2026 at 07:22 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 05 Oct 2026 06:15:00 +0000

Type Values Removed Values Added
Description A vulnerability was detected in linlinjava litemall up to 1.8.0. This affects an unknown part of the file litemall-admin-api/src/main/java/org/linlinjava/litemall/admin/web/AdminAuthController.java of the component Login Endpoint. The manipulation results in improper restriction of excessive authentication attempts. The attack may be performed from remote. A high complexity level is associated with this attack. It is indicated that the exploitability is difficult. The exploit is now public and may be used. The project was informed of the problem early through an issue report but has not responded yet.
Title linlinjava litemall Login Endpoint AdminAuthController.java excessive authentication
First Time appeared Linlinjava
Linlinjava litemall
Weaknesses CWE-307
CWE-799
CPEs cpe:2.3:a:linlinjava:litemall:*:*:*:*:*:*:*:*
Vendors & Products Linlinjava
Linlinjava litemall
References
Metrics cvssV2_0

{'score': 2.6, 'vector': 'AV:N/AC:H/Au:N/C:P/I:N/A:N/E:POC/RL:ND/RC:C'}

cvssV3_0

{'score': 3.7, 'vector': 'CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N/E:P/RL:X/RC:C'}

cvssV3_1

{'score': 3.7, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N/E:P/RL:X/RC:C'}

cvssV4_0

{'score': 6.3, 'vector': 'CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:P'}


Subscriptions

Linlinjava Litemall
cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-10-05T06:00:11.321Z

Reserved: 2026-10-04T16:10:34.297Z

Link: CVE-2026-105237

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-05T06:16:57.997

Modified: 2026-10-05T06:16:57.997

Link: CVE-2026-105237

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-05T07:30:18Z

Weaknesses
  • CWE-307

    Improper Restriction of Excessive Authentication Attempts

  • CWE-799

    Improper Control of Interaction Frequency