Description
A flaw has been found in macrozheng mall 0504e86. This vulnerability affects unknown code of the file /sso/getAuthCode of the component mall-portal Module. Executing a manipulation can lead to weak password recovery. The attack may be launched remotely. This attack is characterized by high complexity. It is stated that the exploitability is difficult. The exploit has been published and may be used. The vendor deleted the GitHub issue for this vulnerability without any explanation. Afterwards the vendor was contacted early about this disclosure via email but did not respond in any way.
Published: 2026-08-09
Score: 6.3 Medium
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A flaw in macrozheng mall 0504e86, located in the /sso/getAuthCode endpoint of the mall-portal module, permits an attacker to manipulate the password recovery process, resulting in a weak authentication reset that could enable unauthorized account access. The vulnerability is based on CWE-640 and directly compromises the integrity of the password reset mechanism.

Affected Systems

Victims of this flaw run the macrozheng mall application, specifically the 0504e86 revision of the mall-portal module. No other versions are listed as affected in the available data, but any deployment using this codebase may be susceptible.

Risk and Exploitability

The CVSS score of 6.3 classifies the issue as medium severity. Although no EPSS score is published, the vulnerability can be exploited remotely and is reported to have a high complexity yet is considered difficult to exploit. The exploit code has been publicly disclosed, and the vulnerability is not currently catalogued in the CISA KEV list.

Generated by OpenCVE AI on August 9, 2026 at 18:20 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade macrozheng mall to a version that addresses the authentication issue, if an official fix is released.
  • If no patch is available, restrict or temporarily disable the /sso/getAuthCode and related password recovery endpoints until a solution is applied.
  • Enforce stronger password reset policies, including mandatory multi‑factor authentication and monitoring for anomalous password‑reset requests to detect and mitigate attempted exploitation.

Generated by OpenCVE AI on August 9, 2026 at 18:20 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 09 Aug 2026 17:30:00 +0000

Type Values Removed Values Added
Description A flaw has been found in macrozheng mall 0504e86. This vulnerability affects unknown code of the file /sso/getAuthCode of the component mall-portal Module. Executing a manipulation can lead to weak password recovery. The attack may be launched remotely. This attack is characterized by high complexity. It is stated that the exploitability is difficult. The exploit has been published and may be used. The vendor deleted the GitHub issue for this vulnerability without any explanation. Afterwards the vendor was contacted early about this disclosure via email but did not respond in any way.
Title macrozheng mall mall-portal getAuthCode password recovery
First Time appeared Macrozheng
Macrozheng mall
Weaknesses CWE-640
CPEs cpe:2.3:a:macrozheng:mall:*:*:*:*:*:*:*:*
Vendors & Products Macrozheng
Macrozheng mall
References
Metrics cvssV2_0

{'score': 2.6, 'vector': 'AV:N/AC:H/Au:N/C:N/I:P/A:N/E:POC/RL:ND/RC:UR'}

cvssV3_0

{'score': 3.7, 'vector': 'CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N/E:P/RL:X/RC:R'}

cvssV3_1

{'score': 3.7, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N/E:P/RL:X/RC:R'}

cvssV4_0

{'score': 6.3, 'vector': 'CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:P'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-08-09T17:15:09.873Z

Reserved: 2026-08-08T19:02:55.433Z

Link: CVE-2026-19361

cve-icon Vulnrichment

No data.

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-09T18:30:04Z

Weaknesses
  • CWE-640

    Weak Password Recovery Mechanism for Forgotten Password