PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-108691 gz-yami CVE debrief

CVE-2026-108691 is a vulnerability in mall4j through version 4.0 that allows authenticated storefront customers to delete other shoppers' cart items due to an improper authorization issue. This is caused by an operator precedence error in the cleanExpiryProdList SQL statement. An attacker can exploit this by sending a single DELETE request to /p/shopCart/cleanExpiryProdList, which can remove every user's cart entries for off-shelf products that do not return when products are restocked.

Vendor
gz-yami
Product
mall4j
CVSS
MEDIUM 5.3
CISA KEV
Not listed in stored evidence
Original CVE published
2026-10-11
Original CVE updated
2026-10-11
Advisory published
2026-10-11
Advisory updated
2026-10-11

Who should care

Defenders responsible for e-commerce platforms, specifically those using mall4j for cart management, should assess exposure and prioritize verification of inventory and compensating controls. Roles include security engineers, e-commerce platform administrators, and incident response teams.

Why it matters

CVE-2026-108691 is a medium-severity vulnerability in mall4j that allows authenticated customers to delete other users' cart items. Defenders should prioritize verifying inventory, assessing exposure, and implementing compensating controls to mitigate potential impacts on data and operations.

  • Potential loss of customer data in cart items.
  • Disruption of e-commerce operations due to unintended cart item deletion.
  • Need for verification of inventory for mall4j version 4.0 or earlier.
  • Potential impact on customer trust and business reputation.

Technical summary

The vulnerability in mall4j through version 4.0 arises from an improper authorization issue that allows authenticated storefront customers to delete other shoppers' cart items. This is achieved through an operator precedence error in the cleanExpiryProdList SQL statement. An attacker can exploit this vulnerability by sending a single DELETE request to /p/shopCart/cleanExpiryProdList, which can remove every user's cart entries for off-shelf products that do not return when products are restocked.

Defensive priority

Defenders should prioritize verifying the presence of this vulnerability in their inventory and assessing exposure, especially in systems where cart item management is critical.

Recommended defensive actions

  • Verify the presence of mall4j version 4.0 or earlier in your inventory.
  • Assess exposure of cart item management functionality to authenticated storefront customers.
  • Implement compensating controls to monitor and limit DELETE requests to /p/shopCart/cleanExpiryProdList.
  • Consider applying patches or updates if available from the vendor.
  • Review system logs for unauthorized access attempts.
  • Conduct regular security audits to identify potential vulnerabilities.
  • Engage with the vendor for support and guidance on remediation.

Evidence notes

The evidence provided includes details from the CVE Program record, NVD vulnerability detail, and source references from GitHub and Vulncheck. However, the corpus does not establish versions, exploitation, impact, or remediation beyond the initial vulnerability description.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-108691 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-108691

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-108691 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-108691

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Source reference

    Unverified legacy reference

    URL: https://github.com/AnkesKasty/cve-request-poc/blob/a7b6d1423555812d8efa26c91c5d0683164b31e5/mall4j/poc_shopcart_clean_expiry_prodlist.py

    [email protected]

  • Source reference

    Unverified legacy reference

    URL: https://github.com/gz-yami/mall4j/blob/ffc672fc1aa4320ce02d0b93853bb456ae0a4dae/yami-shop-api/src/main/java/com/yami/shop/api/controller/ShopCartController.java

    [email protected]

  • Source reference

    Unverified legacy reference

    URL: https://github.com/gz-yami/mall4j/blob/ffc672fc1aa4320ce02d0b93853bb456ae0a4dae/yami-shop-service/src/main/resources/mapper/BasketMapper.xml

    [email protected]

  • Source reference

    Unverified legacy reference

    URL: https://www.vulncheck.com/advisories/mall4j-through-4.0-operator-precedence-error-deletes-other-users-cart-items-via-p-shopcart-cleanexpiryprodlist

    [email protected]

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.