CVE Wiki Pixee · CVE intelligence
← All CVEs

CVE-2026-25858

Critical · CVSS 9.1

macrozheng mall — OTP Disclosure / Unauthenticated Password Reset (Account Takeover)

CVSS
9.1
nvd
EPSS
0.61%
45th pct
KEV
No
Class
oss containerizable
CWE-640

Description

macrozheng mall version 1.0.3 and prior contains an authentication vulnerability in the mall-portal password reset workflow that allows an unauthenticated attacker to reset arbitrary user account passwords using only a victim’s telephone number. The password reset flow exposes the one-time password (OTP) directly in the API response and validates password reset requests solely by comparing the provided OTP to a value stored by telephone number, without verifying user identity or ownership of the telephone number. This enables remote account takeover of any user with a known or guessable telephone number.

Search profile — drives PoC discovery

Symbols mall-portalgetAuthCodeupdatePasswordUmsMemberControllerUmsMemberServicegenerateAuthCodeverifyAuthCodeauthCodetelephoneOTPpasswordResetPasswordParamUmsMember
Keywords CVE-2026-25858macrozheng mall OTP disclosuremall-portal password reset vulnerabilitymacrozheng mall account takeovermall unauthenticated password resetmall authentication bypass OTPmacrozheng mall CWE-640mall portal telephone reset exploitmacrozheng mall 1.0.3 vulnerabilitymall issues 946
Versions: <= 1.0.3

References

Status: enriched · ingested 2026-07-14T18:00:20.000Z · profiled 2026-07-14T18:30:20.000Z