PT-2026-102406 · Mall4J · Mall4J

·

CVE-2026-102363

·

Published

2026-09-28

·

Updated

2026-09-29

CVSS v4.0

6.3

Medium

VectorAV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions mall4j versions prior to 4.1
Description A missing authentication issue exists in the DeliveryController checkDelivery endpoint. This allows unauthenticated attackers to retrieve shipment tracking information, including carrier names, waybill numbers, and complete logistics trails for any order, by providing the order number parameter without ownership verification.
Recommendations Update mall4j to a version later than 4.0. As a temporary workaround, restrict access to the checkDelivery endpoint in the DeliveryController to minimize the risk of unauthorized data disclosure.

Exploit

Fix

Missing Authentication

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-102363

Affected Products

Mall4J