CVE-2026-103538 | ZongXR SuperMarket 1.0.0.0 Order Deletion Endpoint OrderController.java OrderController.deleteOrder orderId missing authentication (Issue 31)

SecurityVulns

A vulnerability was found in ZongXR SuperMarket 1.0.0.0. It has been classified as critical. Affected by this issue is the function OrderController.deleteOrder of the file order/src/main/java/com/supermarket/order/controller/OrderController.java of the component Order Deletion Endpoint. Performing a manipulation of the argument orderId results in missing authentication.

This vulnerability is reported as CVE-2026-103538. The attack is possible to be carried out remotely. Moreover, an exploit is present.

The project was informed of the problem early through an issue report but has not responded yet.VulDB Recent EntriesRead More