rootpwn

critical · CVSS v3 9.1 · CVSS v4 9.3

CVE-2026-102361

Mall4j 4.0 has a missing authentication flaw in the PUT /user/updatePwd endpoint that lets unauthenticated users reset any storefront accoun

Overview

Mall4j 4.0 has a missing authentication flaw in the PUT /user/updatePwd endpoint that lets unauthenticated users reset any storefront account password. This allows attackers to take over customer accounts and access sensitive order data. The vulnerability is critical with a CVSS v3 score of 9.1.

Description

mall4j through 4.0 contains a missing authentication vulnerability in the PUT /user/updatePwd endpoint that allows unauthenticated attackers to reset any storefront account password. Attackers can supply a target username in the request body to overwrite passwords without verification, enabling account takeover and access to orders and personal data.

Impact

The vulnerability compromises confidentiality, integrity, and availability of customer data. Attackers can hijack accounts, view and modify orders, and exfiltrate personal information. Defenders should treat it as a high‑risk threat to customer trust and regulatory compliance.

Remediation

Apply the official patch that enforces authentication on the /user/updatePwd endpoint. If a patch is not yet available, block unauthenticated access to that endpoint via firewall or API gateway, and enforce strong password policies. Monitor logs for unusual password reset activity.

Risk context

Critical severity (CVSS 9.1) with no EPSS data, indicating a high likelihood of exploitation. Immediate action is recommended to mitigate potential account takeovers.

Affected products

  • mall4j 4.0

Scores

Severity
critical
CVSS v2
9.4
CVSS v3
9.1
CVSS v4
9.3
EPSS
—

authentication account takeover password reset mall4j critical web API

← All CVEs