Improper Authorization in Tacomall via OrgStaffServiceImpl
Tacomall 1.0.0 is vulnerable to an improper authorization flaw in the OrgStaffServiceImpl.add function, allowing remote attackers to manipulate isAdmin or jobId arguments to achieve unauthorized access.
CVE search metadata
CVE search record: CVE-2026-102293. Severity: high. CVSS: 7.3. KEV: no. Product: tacomall (1.0.0). Brief: Improper Authorization in Tacomall via OrgStaffServiceImpl. Brief link: https://feed.craftedsignal.io/briefs/2026-09-tacomall-auth-bypass/
A security vulnerability has been identified in the 'tacomall' application version 1.0.0, developed by 'realjerrytang'. The flaw resides in the 'OrgStaffServiceImpl.add' function within the 'ApiMaApplication.java' file of the 'api-admin' backend component. An attacker can exploit this vulnerability by manipulating the 'isAdmin' or 'jobId' arguments during an organizational staff addition request. This improper authorization defect allows remote, unauthenticated, or low-privileged attackers to gain elevated privileges or perform actions intended for administrators. The vulnerability is currently being tracked as CVE-2026-102293, and proof-of-concept exploit code is publicly available, increasing the likelihood of in-the-wild exploitation. Defenders should monitor for unexpected API requests targeting the 'OrgStaffServiceImpl' endpoint.
Impact
Successful exploitation of this vulnerability leads to broken access control, enabling unauthorized administrative actions within the Tacomall environment. Depending on the environment, this could allow an attacker to create new administrative accounts, modify existing user permissions, or extract sensitive organizational staff data. The exposure of administrative functions via an insecure API endpoint poses a high risk to the confidentiality and integrity of the application data.
Recommendation
- Inventory all instances of Tacomall version 1.0.0 and assess the exposure of the 'api-admin' backend.
- Implement strict input validation and server-side authorization checks on the 'OrgStaffServiceImpl.add' API endpoint to verify user identity before processing 'isAdmin' or 'jobId' parameter modifications.
- If patching is not immediately feasible, restrict network access to the management backend using an IP allowlist or VPN, ensuring only authorized administrators can reach the vulnerable API.
- Monitor application server logs for abnormal request patterns targeting 'OrgStaffServiceImpl.add', specifically looking for suspicious modifications to user role parameters.
Immediate actions
Review application logs for attempts to modify isAdmin/jobId parameters
Mitigations
Restrict access to api-admin backend via network controls
CVE-2026-102293