{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/mall4j--4.0/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:mall4j:mall4j:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":9.1,"id":"CVE-2026-102361"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["mall4j (\u003c= 4.0)"],"_cs_severities":["critical"],"_cs_tags":["web-application","authentication-bypass","cve-2026-102361"],"_cs_type":"advisory","_cs_vendors":["mall4j"],"content_html":"\u003cp\u003eThe mall4j application up to version 4.0 contains a critical missing authentication vulnerability in the PUT /user/updatePwd API endpoint. This flaw allows an unauthenticated remote attacker to reset the password for any storefront account by sending a specially crafted request to the application. By supplying a target username in the JSON request body, the application fails to verify the current user's session or identity, directly overwriting the account password with a value provided by the attacker. This vulnerability enables immediate account takeover, granting unauthorized access to storefront order history, personal information, and administrative functionality associated with the compromised account. Organizations utilizing mall4j should verify their exposure and implement access controls or blocking rules for this specific API endpoint until patches are applied.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation results in full account takeover of any storefront user, including administrative accounts. This leads to the exposure of sensitive customer data, order details, and potential financial fraud. The vulnerability affects all deployments of mall4j up to version 4.0, representing a high risk to e-commerce storefronts.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003ePrioritize updating all instances of mall4j to a patched version beyond 4.0 immediately.\u003c/li\u003e\n\u003cli\u003eMonitor web application logs for unauthorized POST or PUT requests to the /user/updatePwd endpoint from external or unexpected internal IP addresses.\u003c/li\u003e\n\u003cli\u003eImplement temporary ingress restrictions or WAF rules to block access to /user/updatePwd from unauthorized sources.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-09-29T00:23:46Z","date_published":"2026-09-29T00:23:46Z","id":"https://feed.craftedsignal.io/briefs/2026-09-mall4j-auth-bypass/","summary":"An unauthenticated remote code execution vulnerability in mall4j through 4.0 allows attackers to reset arbitrary storefront passwords via the PUT /user/updatePwd endpoint.","title":"Authentication Bypass in mall4j via Password Reset Endpoint","url":"https://feed.craftedsignal.io/briefs/2026-09-mall4j-auth-bypass/"}],"language":"en","title":"CraftedSignal Threat Feed - Mall4j (\u003c= 4.0)","version":"https://jsonfeed.org/version/1.1"}