{"id":"CVE-2026-25858","summary":"macrozheng mall \u003c= 1.0.3 Unauthenticated Password Reset via OTP Disclosure","details":"macrozheng mall version 1.0.3 and prior contains an authentication vulnerability in the mall-portal password reset workflow that allows an unauthenticated attacker to reset arbitrary user account passwords using only a victim’s telephone number. The password reset flow exposes the one-time password (OTP) directly in the API response and validates password reset requests solely by comparing the provided OTP to a value stored by telephone number, without verifying user identity or ownership of the telephone number. This enables remote account takeover of any user with a known or guessable telephone number.","modified":"2026-08-12T03:51:44.311356556Z","published":"2026-02-07T21:45:41.186Z","database_specific":{"cna_assigner":"VulnCheck","cwe_ids":["CWE-640"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/25xxx/CVE-2026-25858.json"},"references":[{"type":"WEB","url":"https://www.macrozheng.com/"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/25xxx/CVE-2026-25858.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-25858"},{"type":"ADVISORY","url":"https://www.vulncheck.com/advisories/macrozheng-mall-unauthenticated-password-reset-via-otp-disclosure"},{"type":"REPORT","url":"https://github.com/macrozheng/mall/issues/946"},{"type":"PACKAGE","url":"https://github.com/macrozheng/mall"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/macrozheng/mall","events":[{"introduced":"0"},{"last_affected":"dd617ac3fe89c8083af56bee3364b1e812cda3ed"}],"database_specific":{"extracted_events":[{"introduced":"0"},{"last_affected":"1.0.3"}],"source":["AFFECTED_FIELD","CPE_RANGE"],"cpe":"cpe:2.3:a:macrozheng:mall:*:*:*:*:*:*:*:*"}}],"versions":["v1.0.3","v1.0.2","v1.0.1","v1.0.0"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-25858.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N"}]}