CVE-2026-102363 PUBLISHED

mall4j through 4.0 Unauthenticated Shipment Tracking Disclosure via Order Number

Assigner: VulnCheck
Reserved: 28.09.2026 Published: 28.09.2026 Updated: 28.09.2026

mall4j through 4.0 contains a missing authentication vulnerability in the DeliveryController checkDelivery endpoint that allows unauthenticated attackers to read shipment tracking information by supplying an order number parameter. Attackers can access carrier names, waybill numbers, and complete logistics trails for any order without authentication or ownership verification.

Metrics

CVSS Vector: CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N
CVSS Score: 6.3

Product Status

Vendor gz-yami
Product mall4j
Versions Default: unaffected
  • affected from 0 to 4.0 (incl.)

Credits

  • Mingsheng Lin finder

References

Problem Types

  • Missing Authentication for Critical Function CWE