Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Mon, 28 Sep 2026 23:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | mall4j through 4.0 contains a missing authentication vulnerability in the PUT /user/updatePwd endpoint that allows unauthenticated attackers to reset any storefront account password. Attackers can supply a target username in the request body to overwrite passwords without verification, enabling account takeover and access to orders and personal data. | |
| Title | mall4j through 4.0 Missing Authentication in Password Update Endpoint | |
| Weaknesses | CWE-306 | |
| References |
|
|
| Metrics |
cvssV3_1
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-09-28T23:34:27.140Z
Reserved: 2026-09-28T22:50:08.550Z
Link: CVE-2026-102361
No data.
Status : Received
Published: 2026-09-29T00:17:03.183
Modified: 2026-09-29T00:17:03.183
Link: CVE-2026-102361
No data.
OpenCVE Enrichment
Updated: 2026-09-29T00:30:08Z
-
CWE-306
Missing Authentication for Critical Function