<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>Mall4j - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/vendors/mall4j/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Tue, 29 Sep 2026 00:23:46 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/vendors/mall4j/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>Authentication Bypass in mall4j via Password Reset Endpoint</title><link>https://feed.craftedsignal.io/briefs/2026-09-mall4j-auth-bypass/</link><pubDate>Tue, 29 Sep 2026 00:23:46 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-09-mall4j-auth-bypass/</guid><description>An unauthenticated remote code execution vulnerability in mall4j through 4.0 allows attackers to reset arbitrary storefront passwords via the PUT /user/updatePwd endpoint.</description><content:encoded><![CDATA[<p>The mall4j application up to version 4.0 contains a critical missing authentication vulnerability in the PUT /user/updatePwd API endpoint. This flaw allows an unauthenticated remote attacker to reset the password for any storefront account by sending a specially crafted request to the application. By supplying a target username in the JSON request body, the application fails to verify the current user's session or identity, directly overwriting the account password with a value provided by the attacker. This vulnerability enables immediate account takeover, granting unauthorized access to storefront order history, personal information, and administrative functionality associated with the compromised account. Organizations utilizing mall4j should verify their exposure and implement access controls or blocking rules for this specific API endpoint until patches are applied.</p>
<h2 id="impact">Impact</h2>
<p>Successful exploitation results in full account takeover of any storefront user, including administrative accounts. This leads to the exposure of sensitive customer data, order details, and potential financial fraud. The vulnerability affects all deployments of mall4j up to version 4.0, representing a high risk to e-commerce storefronts.</p>
<h2 id="recommendation">Recommendation</h2>
<ul>
<li>Prioritize updating all instances of mall4j to a patched version beyond 4.0 immediately.</li>
<li>Monitor web application logs for unauthorized POST or PUT requests to the /user/updatePwd endpoint from external or unexpected internal IP addresses.</li>
<li>Implement temporary ingress restrictions or WAF rules to block access to /user/updatePwd from unauthorized sources.</li>
</ul>
]]></content:encoded><category domain="severity">critical</category><category domain="type">advisory</category><category>web-application</category><category>authentication-bypass</category><category>cve-2026-102361</category></item></channel></rss>