CRITICAL
9.1 CVE-2026-102361 Published 29 Sept 2026
Mall4j Storefront Password Reset Authentication Bypass Vulnerability
Worried this affects your website?
mall4j through 4.0 contains a missing authentication vulnerability in the PUT /user/updatePwd endpoint.
Unauthenticated attackers can supply a target username in the request body to reset that storefront account's password without verification.
- Affected versions: mall4j through 4.0
- Attack vector: unauthenticated PUT request to /user/updatePwd
- Impact: account takeover, access to orders and personal data
Reference: CVE-2026-102361 on NVD
← Back to Security News