🔐 CVE Alert

CVE-2026-12258

UNKNOWN 0.0

Inadequate access control in the Hiperdino REST API

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

Inadequate access control in Hiperdino’s REST v1.0 API. The public endpoint ‘customer/check’ could allow an authenticated attacker to enter a telephone number or an email address. When the value entered belongs to a registered customer, the service returns the associated information (email address and telephone number). No authentication is required beyond a static bearer token, and there is no rate limiting or generic error handling. Successful exploitation of this vulnerability could allow a remote attacker to enumerate a user’s contact details, although this would require obtaining a valid static bearer token, constituting an information disclosure vulnerability.

CWE CWE-284
Vendor hiperdino
Product rest api
Published Sep 14, 2026
Last Updated Sep 14, 2026
Stay Ahead of the Next One

Get instant alerts for hiperdino rest api

Be the first to know when new unknown vulnerabilities affecting hiperdino rest api are published — delivered to Slack, Telegram or Discord.

Get Free Alerts → Free · No credit card · 60 sec setup

Affected Versions

Hiperdino / REST API
1.0

References

NVD ↗ CVE.org ↗ EPSS Data ↗
incibe.es: https://www.incibe.es/en/incibe-cert/notices/aviso/inadequate-access-control-hiperdino-rest-api

Credits

Jorge Ramos Santana