CVE-2026-103536 | ZongXR Supermarket 1.0.0.0 save Endpoint OrderController.java OrderController.addOrder userId missing authentication (Issue 32)
A vulnerability was found in ZongXR Supermarket 1.0.0.0 and classified as critical. Affected by this vulnerability is the function OrderController.addOrder of the file order/src/main/java/com/supermarket/order/controller/OrderController.java of the component save Endpoint. Such manipulation of the argument userId leads to missing authentication.
This vulnerability is documented as CVE-2026-103536. The attack can be executed remotely. Additionally, an exploit exists.
The project was informed of the problem early through an issue report but has not responded yet.VulDB Recent EntriesRead More