CVE-2026-82423CWE-841

CVE-2026-82423

Medium · published August 30, 2026

CVSS v3.1
5.4
EPSS
0%
Percentile
16.3
In the wild
Unconfirmed
What it is

A vulnerability has been found in macrozheng mall up to 1.0.3. The affected element is an unknown function of the file /order/paySuccess of the component Payment Status Endpoint. The manipulation of the argument orderId leads to enforcement of behavioral workflow. The attack is possible to be carried out remotely. The vendor deleted the GitHub issue for this vulnerability without any explanation.

The record
Technical detail
CVSS v3.1
5.4 · MEDIUM
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L
CVSS v4.0
5.3 · CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N/E:P
EPSS
0.00250 · 16.3th percentile
Weakness
CWE-841 · Improper Enforcement of Behavioral Workflow
Published
2026-08-30T03:17Z
References (6)
EPSS history
Timeline
  • 30 AUG 16:19Z
    EPSS moved — → 0%
    epss
  • 29 AUG 22:15Z
    macrozheng mall Payment Status Endpoint paySuccess behavioral workflow
    cvelistv5