PatchSiren cyber security CVE debrief
CVE-2026-108691 gz-yami CVE debrief
CVE-2026-108691 is a vulnerability in mall4j through version 4.0 that allows authenticated storefront customers to delete other shoppers' cart items due to an improper authorization issue. This is caused by an operator precedence error in the cleanExpiryProdList SQL statement. An attacker can exploit this by sending a single DELETE request to /p/shopCart/cleanExpiryProdList, which can remove every user's cart entries for off-shelf products that do not return when products are restocked.
- Vendor
- gz-yami
- Product
- mall4j
- CVSS
- MEDIUM 5.3
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-10-11
- Original CVE updated
- 2026-10-11
- Advisory published
- 2026-10-11
- Advisory updated
- 2026-10-11
Who should care
Defenders responsible for e-commerce platforms, specifically those using mall4j for cart management, should assess exposure and prioritize verification of inventory and compensating controls. Roles include security engineers, e-commerce platform administrators, and incident response teams.
Why it matters
CVE-2026-108691 is a medium-severity vulnerability in mall4j that allows authenticated customers to delete other users' cart items. Defenders should prioritize verifying inventory, assessing exposure, and implementing compensating controls to mitigate potential impacts on data and operations.
- Potential loss of customer data in cart items.
- Disruption of e-commerce operations due to unintended cart item deletion.
- Need for verification of inventory for mall4j version 4.0 or earlier.
- Potential impact on customer trust and business reputation.
Technical summary
The vulnerability in mall4j through version 4.0 arises from an improper authorization issue that allows authenticated storefront customers to delete other shoppers' cart items. This is achieved through an operator precedence error in the cleanExpiryProdList SQL statement. An attacker can exploit this vulnerability by sending a single DELETE request to /p/shopCart/cleanExpiryProdList, which can remove every user's cart entries for off-shelf products that do not return when products are restocked.
Defensive priority
Defenders should prioritize verifying the presence of this vulnerability in their inventory and assessing exposure, especially in systems where cart item management is critical.
Recommended defensive actions
- Verify the presence of mall4j version 4.0 or earlier in your inventory.
- Assess exposure of cart item management functionality to authenticated storefront customers.
- Implement compensating controls to monitor and limit DELETE requests to /p/shopCart/cleanExpiryProdList.
- Consider applying patches or updates if available from the vendor.
- Review system logs for unauthorized access attempts.
- Conduct regular security audits to identify potential vulnerabilities.
- Engage with the vendor for support and guidance on remediation.
Evidence notes
The evidence provided includes details from the CVE Program record, NVD vulnerability detail, and source references from GitHub and Vulncheck. However, the corpus does not establish versions, exploitation, impact, or remediation beyond the initial vulnerability description.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-108691 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-108691
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-108691 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-108691
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://github.com/AnkesKasty/cve-request-poc/blob/a7b6d1423555812d8efa26c91c5d0683164b31e5/mall4j/poc_shopcart_clean_expiry_prodlist.py
-
Source reference
Unverified legacy reference
URL: https://github.com/gz-yami/mall4j/blob/ffc672fc1aa4320ce02d0b93853bb456ae0a4dae/yami-shop-api/src/main/java/com/yami/shop/api/controller/ShopCartController.java
-
Source reference
Unverified legacy reference
URL: https://github.com/gz-yami/mall4j/blob/ffc672fc1aa4320ce02d0b93853bb456ae0a4dae/yami-shop-service/src/main/resources/mapper/BasketMapper.xml
-
Source reference
Unverified legacy reference
URL: https://www.vulncheck.com/advisories/mall4j-through-4.0-operator-precedence-error-deletes-other-users-cart-items-via-p-shopcart-cleanexpiryprodlist
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.