CVE-2026-19361: macrozheng mall mall-portal getAuthCode password recovery
A flaw has been found in macrozheng mall 0504e86. This vulnerability affects unknown code of the file /sso/getAuthCode of the component mall-portal Module. Executing a manipulation can lead to weak password recovery. The attack may be launched remotely. This attack is characterized by high complexity. It is stated that the exploitability is difficult. The exploit has been published and may be used. The vendor deleted the GitHub issue for this vulnerability without any explanation. Afterwards the vendor was contacted early about this disclosure via email but did not respond in any way.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-19361?
The severity of CVE-2026-19361 is low with a score of 3.7.
How do I fix CVE-2026-19361?
Fixing CVE-2026-19361 involves applying the latest security patches for the macrozheng mall application.
What impact does CVE-2026-19361 have on password recovery?
CVE-2026-19361 can lead to weak password recovery processes, potentially allowing unauthorized access.
Can CVE-2026-19361 be exploited remotely?
Yes, CVE-2026-19361 can be exploited remotely.
What component is affected by CVE-2026-19361?
CVE-2026-19361 affects the mall-portal module of the macrozheng mall software.