CVE-2026-25858General(macrozheng / mall)

LOWCVSS 9.8 · CRITICAL

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Patch macrozheng mall systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

macrozheng mall version 1.0.3 and prior contains an authentication vulnerability in the mall-portal password reset workflow that allows an unauthenticated attacker to reset arbitrary user account passwords using only a victim’s telephone number. The password reset flow exposes the one-time password (OTP) directly in the API response and validates password reset requests solely by comparing the provided OTP to a value stored by telephone number, without verifying user identity or ownership of the telephone number. This enables remote account takeover of any user with a known or guessable telephone number.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-640

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • mall

Threat summary

  • Patch or workaround signal is available
  • 3 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 2 signals
  • General: 1 classified signal
  • Disclosure: 1 classified signal
  • Peaked at 2 mentions on most recent observed day (2026-02-08)
  • 3 total mentions across 2 days

Affected systems

Vendors
Products
mall

Deep dive

Activity timeline3 mentions / 2d
01122Mentions · 2026-02-07: 1Mentions · 2026-02-08: 2Patch / Workaround · 2026-02-08: 2Technical Details · 2026-02-08: 202-0702-08
Signal classification3 categories
General
133.3%
Disclosure
133.3%
Patch
133.3%
Referenced assets2 URLs
Classification over time
DateTotalLabels
2026-02-071
General1
2026-02-082
Disclosure1Patch1
Full discourse3 posts
  • CVE@CVEnew
    General

    CVE-2026-25858 macrozheng mall version 1.0.3 and prior contains an authentication vulnerability in the mall-portal password reset workflow that allows an unauthenticated attacker to… https://www.cve.org/CVERecord?id=CVE-2026-25858

    Post summary

    The post announces CVE‑2026‑25858 as an authentication vulnerability in macrozheng mall’s password reset process but provides no further technical details, exploit code, or mitigation information.

    00020227
    56.5K followersView on X
  • OffSeq | Adversary Tactics for Cyber Resilience@offseq
    Patch

    🚨 CRITICAL flaw in macrozheng mall ≤1.0.3 lets attackers reset any user's password with just a phone number! Patch ASAP or disable reset function. https://radar.offseq.com/threat/cve-2026-25858-cwe-640-weak-password-recovery-mech-3ff06a38 #OffSeq #CVE202625858 #infosec https://t.co/8Tb0TOjStx

    Post summary

    The tweet alerts that macrozheng mall versions ≤1.0.3 have a critical flaw allowing password resets via phone number alone, urging users to patch or disable the reset feature.

    0000039
    268 followersView on X
  • OffSeq | Adversary Tactics for Cyber Resilience@offseq
    Disclosure

    🚨 CRITICAL vuln in macrozheng mall ≤1.0.3: Weak password reset lets attackers take over any account with just a phone number — no auth needed! Disable resets & enforce MFA now. Details: https://radar.offseq.com/threat/cve-2026-25858-cwe-640-weak-password-recovery-mech-3ff06a38... https://t.co/zKYRwSHJHr

    Post summary

    The tweet announces a critical vulnerability in macrozheng mall (≤1.0.3) that permits account takeover via a weak password reset, and recommends disabling resets and enforcing MFA as a workaround.

    0000055
    268 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appmacrozhengmall---

Explore more