OFFLINE
Awaiting data
Security intelligence
CriticalCritical vulnerability

CVE-2026-102361 (CVSS 9.3)

NVD · officialPublished Sep 29, 2026Risk 50/100

mall4j through 4.0 contains a missing authentication vulnerability in the PUT /user/updatePwd endpoint that allows unauthenticated attackers to reset any storefront account password. Attackers can supply a target username in the request body to overwrite passwords without verification, enabling account takeover and access to orders and personal data.

CVSS
9.3
AV:NetworkAC:LowPR:NoneUI:None

This record is attributed to NVD. Exploitation status and remediation guidance are kept separate from the vulnerability's technical severity.

Open primary source