Skip to main content
CRITICAL

CVE-2026-25858

macrozheng mall <= 1.0.3 Unauthenticated Password Reset via OTP Disclosure

CVSS v3

9.1

CRITICAL

EPSS Score

1.0 %

exploit probability, as of 2026-09-26

CISA KEV

No

known exploited

Exploitation

poc

SSVC status

Description

macrozheng mall version 1.0.3 and prior contains an authentication vulnerability in the mall-portal password reset workflow that allows an unauthenticated attacker to reset arbitrary user account passwords using only a victim’s telephone number. The password reset flow exposes the one-time password (OTP) directly in the API response and validates password reset requests solely by comparing the provided OTP to a value stored by telephone number, without verifying user identity or ownership of the

Technical details

Published
2026-02-07
Last Modified
2026-04-07

Frequently asked questions

What is CVE-2026-25858?

macrozheng mall version 1.0.3 and prior contains an authentication vulnerability in the mall-portal password reset workflow that allows an unauthenticated attacker to reset arbitrary user account passwords using only a victim’s telephone number. The password reset flow exposes the one-time password (OTP) directly in the API response and validates password reset requests solely by comparing the provided OTP to a value stored by telephone number, without verifying user identity or ownership of the

Is CVE-2026-25858 actively exploited?

A proof-of-concept exploit exists for CVE-2026-25858, but active exploitation has not been confirmed at this time.

What is the CVSS score for CVE-2026-25858?

CVE-2026-25858 has a CVSS v3 base score of 9.1 (CRITICAL severity).

Is CVE-2026-25858 affecting your environment?

Use isMalicious to check if any of your IPs or domains are associated with this vulnerability's IOCs.

No credit card required · 500 free checks/month · Free API key