OCTOBER 6, 2026
Live Feed
Back to database
Case File

CVE-2026-102361

CRITICAL · CVSS 9.1 EPSS 0.37% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-09-29 · Last synced 2026-10-06

CyberRota Analysis

AI-Generated

The vulnerability allows unauthenticated attackers to exploit the PUT /user/updatePwd endpoint in mall4j versions up to 4.0, enabling them to reset any storefront account password by simply providing a target username. This critical flaw poses a significant risk of account takeover, granting attackers access to sensitive orders and personal data. Organizations using mall4j should prioritize immediate remediation to protect user accounts and sensitive information.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-102361
Severity
CRITICAL
CVSS
9.1
EPSS
0.37%

Original NVD Description

mall4j through 4.0 contains a missing authentication vulnerability in the PUT /user/updatePwd endpoint that allows unauthenticated attackers to reset any storefront account password. Attackers can supply a target username in the request body to overwrite passwords without verification, enabling account takeover and access to orders and personal data.