Skip to content
CVE-2026-103536: Authentication Flaw in ZongXR Supermarket

CVE-2026-103536: Authentication Flaw in ZongXR Supermarket

First seen 1 Oct 2026, 10:58 UTC • •

Article Content

Browse articles
ThreatCluster AI
ThreatCluster •October 1, 2026 at 12:05 UTC
  • •CVE-2026-103536 allows unauthorized order submissions in ZongXR Supermarket.
  • •The vulnerability is publicly disclosed but lacks an available patch.
  • •Affected systems include internet-facing deployments connected to customer databases.

A missing authentication vulnerability has been identified in ZongXR Supermarket version 1.0.0.0. The flaw exists in the OrderController.addOrder function, allowing unauthenticated attackers to submit orders using any user's identity. This could lead to the creation of fraudulent orders and disrupt fulfillment processes. The vulnerability is publicly disclosed as CVE-2026-103536 with a CVSS score of 6.9, categorized as medium severity. Although the project was notified of the issue, no response or patch has been provided yet. The vulnerable endpoint is accessible over the internet, posing a significant risk to deployments connected to live checkout and customer databases. Security professionals are advised to monitor order submissions and audit logs for unusual activity.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated just now How this analysis works

Timeline

2026-10-01
CVE-2026-103536 published
A critical missing authentication vulnerability in ZongXR Supermarket was disclosed, allowing unauthorized order submissions.
Redpacketsecurity
2026-10-01
GitHub issue reported
A GitHub issue confirmed the vulnerability as a 0-day, detailing the lack of authentication checks in the order creation endpoint.
github.com

More articles in this cluster (2)

Following this threat?

Track CVE-2026-103536 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed

Common questions

Which versions are affected?
ZongXR Supermarket version 1.0.0.0 is affected by the vulnerability.
Is there a patch available?
No, the vendor has not responded with a patch or fix for the vulnerability.
What should I monitor for?
Monitor order submissions for discrepancies in user identifiers and audit logs for unusual activity.