CRITICAL 9.1 CVE-2026-102361 Published 29 Sept 2026

Mall4j Storefront Password Reset Authentication Bypass Vulnerability

Worried this affects your website?

mall4j through 4.0 contains a missing authentication vulnerability in the PUT /user/updatePwd endpoint.

Unauthenticated attackers can supply a target username in the request body to reset that storefront account's password without verification.

  • Affected versions: mall4j through 4.0
  • Attack vector: unauthenticated PUT request to /user/updatePwd
  • Impact: account takeover, access to orders and personal data

Reference: CVE-2026-102361 on NVD

← Back to Security News