CVE-2026-25858
macrozheng mall version 1.0.3 and prior contains an authentication vulnerability in the mall-portal password reset workflow that allows an unauthenticated attacker to reset arbitrary user account passwords using only a victim’s telephone number. The password reset flow exposes the one-time password (OTP) directly in the API response and validates password reset requests solely by comparing the provided OTP to a value stored by telephone number, without verifying user identity or ownership of the telephone number. This enables remote account takeover of any user with a known or guessable telephone number.
Published:Feb 7, 2026
Last Modified:Apr 15, 2026
EPS:Feb 7, 2026
EPSS Score:0.00334
CVSS Score:9.1
Affected Products
Vendor
Product
Action
Vendor
Macrozheng
Product
Mall
Macrozheng
Mall
Vendor
Newbee-mall Project
Product
Newbee-mall
Newbee-mall Project
Newbee-mall
Exploits
No exploit reference
Common Weakness Enumeration
Common Attack Pattern Enumeration and Classification (CAPEC)
Related CVEs
Common Vulnerability Scoring System
Attack Vector
Network
Adjacent
Local
Physical
Privileges Required
None
Low
High
User Interaction
None
Required
Scope
Unchanged
Changed
Confidentiality
None
Low
High
Integrity
None
Low
High
Availability
None
Low
High
