Authentication Bypass in mall4j via Password Reset Endpoint
An unauthenticated remote code execution vulnerability in mall4j through 4.0 allows attackers to reset arbitrary storefront passwords via the PUT /user/updatePwd endpoint.
CVE search metadata
CVE search record: CVE-2026-102361. Severity: critical. CVSS: 9.1. KEV: no. Product: mall4j (<= 4.0). Brief: Authentication Bypass in mall4j via Password Reset Endpoint. Brief link: https://feed.craftedsignal.io/briefs/2026-09-mall4j-auth-bypass/
The mall4j application up to version 4.0 contains a critical missing authentication vulnerability in the PUT /user/updatePwd API endpoint. This flaw allows an unauthenticated remote attacker to reset the password for any storefront account by sending a specially crafted request to the application. By supplying a target username in the JSON request body, the application fails to verify the current user's session or identity, directly overwriting the account password with a value provided by the attacker. This vulnerability enables immediate account takeover, granting unauthorized access to storefront order history, personal information, and administrative functionality associated with the compromised account. Organizations utilizing mall4j should verify their exposure and implement access controls or blocking rules for this specific API endpoint until patches are applied.
Impact
Successful exploitation results in full account takeover of any storefront user, including administrative accounts. This leads to the exposure of sensitive customer data, order details, and potential financial fraud. The vulnerability affects all deployments of mall4j up to version 4.0, representing a high risk to e-commerce storefronts.
Recommendation
- Prioritize updating all instances of mall4j to a patched version beyond 4.0 immediately.
- Monitor web application logs for unauthorized POST or PUT requests to the /user/updatePwd endpoint from external or unexpected internal IP addresses.
- Implement temporary ingress restrictions or WAF rules to block access to /user/updatePwd from unauthorized sources.
Immediate actions
Review web server access logs for any PUT requests to /user/updatePwd
Mitigations
Upgrade mall4j to a version beyond 4.0 once available
CVE-2026-102361
Detection coverage 1
Detects CVE-2026-102361 Exploitation - Unauthorized Password Reset Request
criticalDetects exploitation attempts against CVE-2026-102361 where unauthenticated users attempt to access the updatePwd endpoint.
Detection queries are available on the platform. Get full rules →