{"id":"CVE-2026-79406","summary":"macrozheng mall quantity OmsCartItemServiceImpl.updateQuantity logic error","details":"A security vulnerability has been detected in macrozheng mall up to 1.0.3. Affected is the function OmsCartItemServiceImpl.updateQuantity of the file /cart/update/quantity. The manipulation of the argument quantity leads to business logic errors. The attack may be initiated remotely. The vendor deleted the GitHub issue for this vulnerability without any explanation.","modified":"2026-08-28T03:30:24.866877896Z","published":"2026-08-25T13:00:09.821Z","database_specific":{"cwe_ids":["CWE-840"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/79xxx/CVE-2026-79406.json","cna_assigner":"VulDB"},"references":[{"type":"WEB","url":"https://github.com/macrozheng/mall/"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/79xxx/CVE-2026-79406.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-79406"},{"type":"ADVISORY","url":"https://vuldb.com/cve/CVE-2026-79406"},{"type":"ADVISORY","url":"https://vuldb.com/submit/886961"},{"type":"ADVISORY","url":"https://vuldb.com/vuln/394944"},{"type":"REPORT","url":"https://github.com/macrozheng/mall/issues/984"},{"type":"REPORT","url":"https://vuldb.com/vuln/394944/cti"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/macrozheng/mall","events":[{"introduced":"470c40eb1656485e53fa175afd7c05d506b42e02"},{"last_affected":"dd617ac3fe89c8083af56bee3364b1e812cda3ed"}],"database_specific":{"source":"AFFECTED_FIELD","extracted_events":[{"introduced":"1.0.0"},{"last_affected":"1.0.0"},{"introduced":"1.0.1"},{"last_affected":"1.0.1"},{"introduced":"1.0.2"},{"last_affected":"1.0.2"},{"introduced":"1.0.3"},{"last_affected":"1.0.3"}]}}],"versions":["1.0.0","1.0.1","1.0.2","1.0.3","v1.0.3","v1.0.2","v1.0.1","v1.0.0"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-79406.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X"}]}