critical · CVSS v3 9.1 · CVSS v4 9.3
CVE-2026-102361
Mall4j 4.0 has a missing authentication flaw in the PUT /user/updatePwd endpoint that lets unauthenticated users reset any storefront accoun
Overview
Mall4j 4.0 has a missing authentication flaw in the PUT /user/updatePwd endpoint that lets unauthenticated users reset any storefront account password. This allows attackers to take over customer accounts and access sensitive order data. The vulnerability is critical with a CVSS v3 score of 9.1.
Description
mall4j through 4.0 contains a missing authentication vulnerability in the PUT /user/updatePwd endpoint that allows unauthenticated attackers to reset any storefront account password. Attackers can supply a target username in the request body to overwrite passwords without verification, enabling account takeover and access to orders and personal data.
Impact
The vulnerability compromises confidentiality, integrity, and availability of customer data. Attackers can hijack accounts, view and modify orders, and exfiltrate personal information. Defenders should treat it as a high‑risk threat to customer trust and regulatory compliance.
Remediation
Apply the official patch that enforces authentication on the /user/updatePwd endpoint. If a patch is not yet available, block unauthenticated access to that endpoint via firewall or API gateway, and enforce strong password policies. Monitor logs for unusual password reset activity.
Risk context
Critical severity (CVSS 9.1) with no EPSS data, indicating a high likelihood of exploitation. Immediate action is recommended to mitigate potential account takeovers.
Affected products
- mall4j 4.0
Scores
- Severity
- critical
- CVSS v2
- 9.4
- CVSS v3
- 9.1
- CVSS v4
- 9.3
- EPSS
- —