---
id: CVE-2026-108691
title: >-
  mall4j through 4.0 contains an improper authorization vulnerability that
  allows authenticated storefront customers to delete other shoppers' cart items
  through an operator precedence error in the cleanExpiryProdList SQL statement
summary: >-
  mall4j through 4.0 contains an improper authorization vulnerability that
  allows authenticated storefront customers to delete other shoppers' cart items
  through an operator precedence error in the cleanExpiryProdList SQL statement.
  Attack…
severity: medium
cvss: 5.4
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L'
cwe:
  - CWE-783
published: '2026-10-11'
updated: '2026-10-11'
sourceUpdated: '2026-10-11T02:16:37.210'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-108691'
references:
  - url: >-
      https://github.com/AnkesKasty/cve-request-poc/blob/a7b6d1423555812d8efa26c91c5d0683164b31e5/mall4j/poc_shopcart_clean_expiry_prodlist.py
    label: disclosure@vulncheck.com
  - url: >-
      https://github.com/gz-yami/mall4j/blob/ffc672fc1aa4320ce02d0b93853bb456ae0a4dae/yami-shop-api/src/main/java/com/yami/shop/api/controller/ShopCartController.java#L188-L194
    label: disclosure@vulncheck.com
  - url: >-
      https://github.com/gz-yami/mall4j/blob/ffc672fc1aa4320ce02d0b93853bb456ae0a4dae/yami-shop-service/src/main/resources/mapper/BasketMapper.xml#L49-L62
    label: disclosure@vulncheck.com
  - url: >-
      https://www.vulncheck.com/advisories/mall4j-through-4.0-operator-precedence-error-deletes-other-users-cart-items-via-p-shopcart-cleanexpiryprodlist
    label: disclosure@vulncheck.com
tags:
  - nvd
ingestedAt: '2026-10-11T02:38:44.033Z'
---

## Overview

mall4j through 4.0 contains an improper authorization vulnerability that allows authenticated storefront customers to delete other shoppers' cart items through an operator precedence error in the cleanExpiryProdList SQL statement. Attackers can send one DELETE request to /p/shopCart/cleanExpiryProdList to remove every user's cart entries for off-shelf products, which do not return when products are restocked.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
