Inadequate access control in Hiperdino’s REST v1.0 API. The public endpoint ‘customer/check’ could allow an authenticated attacker to enter a telephone number or an email address. When the value entered belongs to a registered customer, the service returns the associated information (email address and telephone number). No authentication is required beyond a static bearer token, and there is no rate limiting or generic error handling. Successful exploitation of this vulnerability could allow a remote attacker to enumerate a user’s contact details, although this would require obtaining a valid static bearer token, constituting an information disclosure vulnerability.

Project Subscriptions

Vendors Products
Hiperdino Subscribe
Rest Api Subscribe
Advisories

No advisories yet.

Fixes

Solution

No solution has been reported as yet.


Workaround

No workaround given by the vendor.

History

Mon, 14 Sep 2026 12:30:00 +0000

Type Values Removed Values Added
Description Inadequate access control in Hiperdino’s REST v1.0 API. The public endpoint ‘customer/check’ could allow an authenticated attacker to enter a telephone number or an email address. When the value entered belongs to a registered customer, the service returns the associated information (email address and telephone number). No authentication is required beyond a static bearer token, and there is no rate limiting or generic error handling. Successful exploitation of this vulnerability could allow a remote attacker to enumerate a user’s contact details, although this would require obtaining a valid static bearer token, constituting an information disclosure vulnerability.
Title Inadequate access control in the Hiperdino REST API
First Time appeared Hiperdino
Hiperdino rest Api
Weaknesses CWE-284
CPEs cpe:2.3:a:hiperdino:rest_api:1.0:*:*:*:*:*:*:*
Vendors & Products Hiperdino
Hiperdino rest Api
References
Metrics cvssV4_0

{'score': 9.2, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:H/SI:N/SA:N'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: INCIBE

Published:

Updated: 2026-09-14T12:11:13.182Z

Reserved: 2026-06-15T09:37:00.376Z

Link: CVE-2026-12258

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-14T13:17:33.290

Modified: 2026-09-14T13:17:33.290

Link: CVE-2026-12258

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses