CVE-2026-102361: mall4j through 4.0 Missing Authentication in Password Update Endpoint
mall4j through 4.0 contains a missing authentication vulnerability in the PUT /user/updatePwd endpoint that allows unauthenticated attackers to reset any storefront account password. Attackers can supply a target username in the request body to overwrite passwords without verification, enabling account takeover and access to orders and personal data.
Affected Software
Event History
Frequently Asked Questions
Which deployments are affected?
mall4j versions through 4.0 are affected. The vulnerable endpoint is the storefront account password update endpoint, PUT /user/updatePwd.
What does an attacker need to exploit this issue?
An attacker needs network access to the vulnerable endpoint and a target storefront username. No authentication, prior privileges, or user interaction is required.
What is the impact of a successful attack?
An attacker can overwrite the password for a chosen storefront account and take it over. This can provide access to the account's orders and personal data.