Act nowDisclosed

Advisory · CVE-2026-102361

Unauthenticated password reset hands over any mall4j storefront account

mall4j through 4.0 leaves PUT /user/updatePwd without authentication, letting anyone reset any storefront account password by supplying the target username in the request body.

Vendor
gz-yami
Product
mall4j
Identifier / CWE
CVE-2026-102361
CWE-306
Action timing
Immediate
ELI5

Explain it like I’m five

The storefront's password-change door has no lock. Anyone who knows an account's username can walk up and set a new password for it, no old password or login needed.

SIMPLIFIED_ATTACK_PATH03 STEPS
  1. 01Unauthenticated request

    An attacker sends a PUT request to /user/updatePwd with a victim's username in the request body.

  2. 02No verification

    The endpoint overwrites the account password without requiring authentication or any verification of the requester.

  3. 03Account takeover

    The attacker logs in with the new password and gains access to the victim's orders and personal data.

What happened

mall4j through 4.0 contains a missing authentication vulnerability in the PUT /user/updatePwd endpoint. The endpoint overwrites a storefront account’s password based solely on the username supplied in the request body, with no authentication or verification of the caller. An unauthenticated remote attacker can therefore reset the password of any account whose username they know or can guess, take over the account, and access its orders and personal data. A public proof of concept has been disclosed.

What to do

  1. Inventory mall4j storefront deployments, including test, staging, and individually managed instances.
  2. Upgrade mall4j to a release newer than 4.0 that addresses the missing authentication once the vendor ships it.
  3. Restrict network access to the storefront API while remediation is underway.
  4. Review application logs for PUT /user/updatePwd requests, especially ones changing passwords for accounts the requester does not own.
  5. Force password resets and rotate session tokens for accounts that may have been affected.
  6. Determine whether orders, personal data, or payment-adjacent information were accessed through taken-over accounts.

Management note

This is an unauthenticated, single-request path to full account takeover in a customer-facing commerce platform. Treat password-reset hygiene and log review as one task, and assume customer data exposure until logs show otherwise.