---
id: CVE-2026-102363
title: >-
  mall4j through 4.0 contains a missing authentication vulnerability in the
  DeliveryController checkDelivery endpoint that allows unauthenticated
  attackers to read shipment tracking information by supplying an order number
  parameter
summary: >-
  mall4j through 4.0 contains a missing authentication vulnerability in the
  DeliveryController checkDelivery endpoint that allows unauthenticated
  attackers to read shipment tracking information by supplying an order number
  parameter. Attac…
severity: low
cvss: 3.7
cvssVector: 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N'
cwe:
  - CWE-306
vendor: gz-yami
product: mall4j
affected:
  - mall4j <= 4.0
published: '2026-09-29'
updated: '2026-09-29'
sourceUpdated: '2026-09-29T00:17:03.483'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-102363'
references:
  - url: >-
      https://github.com/LinYuanyi1/cve-request-poc/blob/114b3f0d149e50a7678f591bf8043399fc9ac96c/mall4j/A08_delivery_check_anonymous.py
    label: disclosure@vulncheck.com
  - url: 'https://github.com/gz-yami/mall4j'
    label: disclosure@vulncheck.com
  - url: >-
      https://github.com/gz-yami/mall4j/blob/ffc672fc1aa4320ce02d0b93853bb456ae0a4dae/yami-shop-api/src/main/java/com/yami/shop/api/controller/DeliveryController.java#L47-L63
    label: disclosure@vulncheck.com
  - url: >-
      https://www.vulncheck.com/advisories/mall4j-through-4.0-unauthenticated-shipment-tracking-disclosure-via-order-number
    label: disclosure@vulncheck.com
tags:
  - nvd
  - cve.org
ingestedAt: '2026-09-29T00:24:04.803Z'
---

## Overview

mall4j through 4.0 contains a missing authentication vulnerability in the DeliveryController checkDelivery endpoint that allows unauthenticated attackers to read shipment tracking information by supplying an order number parameter. Attackers can access carrier names, waybill numbers, and complete logistics trails for any order without authentication or ownership verification.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
