CVE-2026-103536

HIGH Status: Received

CVSS Scores

CVSS v3.x Base Score
7.3
HIGH
CVSS v2 Base Score
7.5
HIGH

Description

A vulnerability was identified in ZongXR Supermarket 1.0.0.0. Affected by this vulnerability is the function OrderController.addOrder of the file order/src/main/java/com/supermarket/order/controller/OrderController.java of the component save Endpoint. Such manipulation of the argument userId leads to missing authentication. The attack can be executed remotely. The exploit is publicly available and might be used. The project was informed of the problem early through an issue report but has not responded yet.

Published
October 1, 2026 5:17 AM
Last Modified
October 1, 2026 5:17 AM
Source
[email protected]

Weaknesses (CWE)

CWE-287 CWE-306

References

Contact Us

Get the CyboWatch SIEM platform, hosting, and 24×7 SOC analysts. Call or email us to get started.