OCTOBER 8, 2026
Live Feed
Back to database
Case File

CVE-2026-102293

HIGH · CVSS 7.3 EPSS 0.28% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-09-29 · Last synced 2026-10-08

CyberRota Analysis

AI-Generated

A high-severity vulnerability exists in the Java component of realjerrytang tacomall 1.0.0, specifically within the OrgStaffServiceImpl.add function of ApiMaApplication.java, where improper authorization can be triggered through manipulation of the isAdmin/jobId argument. This flaw allows for potential remote exploitation, as publicly available exploits may be utilized by attackers. Organizations using this software should prioritize immediate remediation to mitigate the risk of unauthorized access.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Detected Signals
exploit
GitHub PoC Links

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-102293
Severity
HIGH
CVSS
7.3
EPSS
0.28%
Java

Original NVD Description

A vulnerability was identified in realjerrytang tacomall 1.0.0. Impacted is the function OrgStaffServiceImpl.add of the file ApiMaApplication.java of the component api-admin Backend. The manipulation of the argument isAdmin/jobId leads to improper authorization. Remote exploitation of the attack is possible. The exploit is publicly available and might be used.