logo

CVE-2026-10070 | macrozheng mall up to 1.0.3 Super Admin Password /admin/update/ improper authorization (Issue 970)

ID: 38b5b03e-a8bc-5309-83b3-1ed6514ae3e9

STIX ID: report--38b5b03e-a8bc-5309-83b3-1ed6514ae3e9

Feed Name: VulDB Recent Entries

Threat Score
50/100

Date Published: 2026-05-29

Date Updated: 2026-05-29

Author: vuldb.com

...
...

This advisory describes a critical improper-authorization vulnerability (CVE-2026-10070) in macrozheng mall ≤1.0.3 affecting the /admin/update Super Admin Password Handler; the issue can impact confidentiality, integrity and availability, is remotely reachable though requires additional authentication, no public exploit exists, and the vendor deleted the GitHub issue and did not respond to disclosure.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.