Junglewise Threat Intelligence

CVE-2026-10070: macrozheng mall improper authorization in Super Admin Password Handler

CVE-2026-10070 · Severity: medium · CVSS 4.7 · Published 2026-05-29

Technologies: Macrozheng Mall. Vendors: Macrozheng.

Executive brief

macrozheng mall is an e-commerce platform used for managing online storefronts and backend operations. A security flaw in the administrative password handling component allows for improper authorization during updates. If exploited, an attacker could potentially manipulate administrative settings or credentials, leading to unauthorized access to the management system and sensitive business data.

Technical details

An improper authorization vulnerability (CWE-285/CWE-266) exists in macrozheng mall versions up to 1.0.3. The flaw is located within the Super Admin Password Handler component, specifically affecting the /admin/update/ endpoint. A remote attacker with high privileges can manipulate requests to this endpoint to bypass intended authorization controls. This could allow for unauthorized modification of administrative credentials or settings. The vendor has reportedly deleted the original issue report and has not provided a patch or official response.

Affected products

  • macrozheng mall up to 1.0.3

Timeline

  • 2026-05-29: advisory: NVD publication date

References

Related threats