Insufficient Session Expiration in mall4j by Yami Technologies
CVE-2026-102367
Key Information:
Badges
What is CVE-2026-102367?
The mall4j product by Yami Technologies has a vulnerability in its token refresh mechanism that allows disabled user accounts to renew their sessions indefinitely. This occurs because the system fails to validate the enabled flag during the session renewal process at the POST /token/refresh endpoint. As a result, deactivated accounts can maintain unauthorized access that user account disables were intended to prevent. Developers and administrators should take immediate action to address this vulnerability to safeguard user data and maintain system integrity.
Affected Version(s)
mall4j 0 <= 4.0
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved
