← Back to search

CVE-2026-102361

9.1 CRITICALpublic exploit available

Published 2026-09-29 · Updated 2026-09-29

AI risk analysis

Summary
The flaw allows unauthenticated attackers to reset any storefront account password through the PUT /user/updatePwd endpoint, enabling account takeover and access to sensitive data.
Exploitability
Exploitation is relatively easy as it requires no authentication and can be performed by supplying a target username in the request body.
Blast radius
If exploited, attackers can gain full access to orders and personal data of any storefront account, leading to significant data breaches and potential financial loss.
Detection
No reliable host or network indicator is derivable from the published description.
Prioritized remediation
Upgrade to mall4j 4.0 or later.
auth-bypasswebpassword-reset

Analysis generated locally by qwen2.5:7b-instruct (no data left the box). AI-assisted — verify against primary sources before acting.

NVD description

mall4j through 4.0 contains a missing authentication vulnerability in the PUT /user/updatePwd endpoint that allows unauthenticated attackers to reset any storefront account password. Attackers can supply a target username in the request body to overwrite passwords without verification, enabling account takeover and access to orders and personal data.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N

Weaknesses

CWE-306

Public exploit & PoC references

All references

Source data: NVD (nvd.nist.gov), public domain. Exploit-DB.ai adds local AI analysis for defensive use only.

Related CVEs

Related by shared AI tags and CWE weakness class. Browse the full archive.