CVE-2026-102363: Gz-Yami MALL4J

Low severity, CVSS 3.7. EPSS: 0.3% chance of exploitation in the next 30 days.

mall4j through 4.0 contains a missing authentication vulnerability in the DeliveryController checkDelivery endpoint that allows unauthenticated attackers to read shipment tracking information by supplying an order number parameter. Attackers can access carrier names, waybill numbers, and complete logistics trails for any order without authentication or ownership verification.

Affected products

  • Gz-Yami MALL4J: up to and including 4.0

Published 2026-09-29. Last modified 2026-09-30.