PT-2026-22212 · Unknown · Hoppscotch

·

CVE-2026-28217

·

Publicado

2026-02-26

·

Atualizado

2026-02-27

CVSS v3.1

6.5

Média

VetorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions hoppscotch versions prior to 2026.2.0
Description The userCollection GraphQL query in hoppscotch does not verify ownership before returning collection data, including potentially sensitive information like HTTP requests and headers, to authenticated users. This is an Insecure Direct Object Reference (IDOR) issue stemming from a missing authorization check. The query accepts an arbitrary collection ID and returns the full collection data to any authenticated user, regardless of ownership.
Recommendations Update to version 2026.2.0 or later.

Exploit

Correção

Missing Authorization

IDOR

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2026-28217
GHSA-M5PG-R4JP-QQ75

Produtos afetados

Hoppscotch