---
id: CVE-2026-82364
title: A security vulnerability has been detected in macrozheng mall up to 1.0.3
summary: >-
  A security vulnerability has been detected in macrozheng mall up to 1.0.3.
  This impacts an unknown function of the file /order/submit of the component
  Order Submission. The manipulation leads to race condition. It is possible to
  initiate…
severity: medium
cvss: 4.2
cvssVector: 'CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:L'
cwe:
  - CWE-362
published: '2026-08-29'
updated: '2026-08-29'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-82364'
references:
  - url: 'https://github.com/macrozheng/mall/'
    label: cna@vuldb.com
  - url: 'https://github.com/macrozheng/mall/issues/983'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/cve/CVE-2026-82364'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/submit/887361'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/vuln/396780'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/vuln/396780/cti'
    label: cna@vuldb.com
tags:
  - nvd
ingestedAt: '2026-08-30T07:49:08.258Z'
epss: 0.0029
epssPercentile: 0.19128
---

## Overview

A security vulnerability has been detected in macrozheng mall up to 1.0.3. This impacts an unknown function of the file /order/submit of the component Order Submission. The manipulation leads to race condition. It is possible to initiate the attack remotely. The attack is considered to have high complexity. The exploitability is said to be difficult. The vendor deleted the GitHub issue for this vulnerability without and explanation.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
