CVE-2026-102362: mall4j through 4.0 Missing Authentication in Product Review Deletion
Published Sep 28, 2026
·Updated
mall4j through 4.0 fails to implement authentication controls on the DELETE /prodComm endpoint in ProdCommController. Unauthenticated attackers can delete arbitrary product reviews by supplying the prodCommId parameter without authorization checks.
Affected Software
1 affected component
mall4j mall4j<=4.0
Event History
Sep 28, 2026
CVE Published
via MITRE·11:34 PM
Data Sourced
via MITRE·11:34 PM
DescriptionSeverityWeakness
Sep 29, 2026
Data Sourced
via NVD·12:17 AM
DescriptionSeverityWeakness
Apr 26, 58713
Event
via NVD·04:51 AM
Frequently Asked Questions
1
Who can exploit this issue?
Any unauthenticated remote attacker who can reach the DELETE /prodComm endpoint can exploit it. No credentials or user interaction are required.
2
What does an attacker need to provide?
The attacker needs a prodCommId parameter identifying the product review to delete. The endpoint does not perform authorization checks for the deletion.
3
Which deployments are affected?
mall4j versions through 4.0 are affected. Deployments exposing the vulnerable endpoint are at risk because authentication is missing on that route.