{"id":"CVE-2026-102364","title":"mall4j through 4.0 fails to validate the sysType field in sa-token sessions, allowing storefront customers to authenticate as back-office users by reusing their session tokens","summary":"mall4j through 4.0 fails to validate the sysType field in sa-token sessions, allowing storefront customers to authenticate as back-office users by reusing their session tokens. Attackers can register on the public storefront and use thei…","severity":"medium","cvss":5.4,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N","cwe":["CWE-287"],"vendor":"gz-yami","product":"mall4j","affected":["mall4j <= 4.0"],"published":"2026-09-29","updated":"2026-09-29","sourceUpdated":"2026-09-29T00:17:03.633","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-102364","references":[{"url":"https://github.com/LinYuanyi1/cve-request-poc/blob/114b3f0d149e50a7678f591bf8043399fc9ac96c/mall4j/A05_sys_menu_missing_perm.py","label":"disclosure@vulncheck.com"},{"url":"https://github.com/LinYuanyi1/cve-request-poc/blob/114b3f0d149e50a7678f591bf8043399fc9ac96c/mall4j/A09_admin_read_endpoints_bfla.py","label":"disclosure@vulncheck.com"},{"url":"https://github.com/gz-yami/mall4j","label":"disclosure@vulncheck.com"},{"url":"https://github.com/gz-yami/mall4j/blob/ffc672fc1aa4320ce02d0b93853bb456ae0a4dae/yami-shop-security/yami-shop-security-common/src/main/java/com/yami/shop/security/common/filter/AuthFilter.java#L60-L119","label":"disclosure@vulncheck.com"},{"url":"https://www.vulncheck.com/advisories/mall4j-through-4.0-improper-authentication-accepts-storefront-tokens-on-admin-api","label":"disclosure@vulncheck.com"}],"tags":["nvd","cve.org"],"ingestedAt":"2026-09-29T00:24:04.804Z","slug":"CVE-2026-102364","body":"## Overview\n\nmall4j through 4.0 fails to validate the sysType field in sa-token sessions, allowing storefront customers to authenticate as back-office users by reusing their session tokens. Attackers can register on the public storefront and use their customer session token to access admin endpoints lacking @PreAuthorize permission checks, including menu listings, file uploads, and configuration endpoints.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"sunlit","depthScore":30,"depthScoreParts":{"impact":29.7,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}