Description
Inadequate access control in Hiperdino’s REST v1.0 API. The public endpoint ‘customer/check’ could allow an authenticated attacker to enter a telephone number or an email address. When the value entered belongs to a registered customer, the service returns the associated information (email address and telephone number). No authentication is required beyond a static bearer token, and there is no rate limiting or generic error handling. Successful exploitation of this vulnerability could allow a remote attacker to enumerate a user’s contact details, although this would require obtaining a valid static bearer token, constituting an information disclosure vulnerability.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
Vendor Solution
No solution has been reported as yet.
Tracking
Sign in to view the affected projects.
Advisories
No advisories yet.
References
History
Mon, 14 Sep 2026 12:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Inadequate access control in Hiperdino’s REST v1.0 API. The public endpoint ‘customer/check’ could allow an authenticated attacker to enter a telephone number or an email address. When the value entered belongs to a registered customer, the service returns the associated information (email address and telephone number). No authentication is required beyond a static bearer token, and there is no rate limiting or generic error handling. Successful exploitation of this vulnerability could allow a remote attacker to enumerate a user’s contact details, although this would require obtaining a valid static bearer token, constituting an information disclosure vulnerability. | |
| Title | Inadequate access control in the Hiperdino REST API | |
| First Time appeared |
Hiperdino
Hiperdino rest Api |
|
| Weaknesses | CWE-284 | |
| CPEs | cpe:2.3:a:hiperdino:rest_api:1.0:*:*:*:*:*:*:* | |
| Vendors & Products |
Hiperdino
Hiperdino rest Api |
|
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: INCIBE
Published:
Updated: 2026-09-14T12:11:13.182Z
Reserved: 2026-06-15T09:37:00.376Z
Link: CVE-2026-12258
No data.
Status : Received
Published: 2026-09-14T13:17:33.290
Modified: 2026-09-14T13:17:33.290
Link: CVE-2026-12258
No data.
OpenCVE Enrichment
No data.
Weaknesses