Inadequate access control in Hiperdino’s REST v1.0 API. The public endpoint ‘customer/check’ could allow an authenticated attacker to enter a telephone number or an email address. When the value entered belongs to a registered customer, the service returns the associated information (email address and telephone number). No authentication is required beyond a static bearer token, and there is no rate limiting or generic error handling. Successful exploitation of this vulnerability could allow a remote attacker to enumerate a user’s contact details, although this would require obtaining a valid static bearer token, constituting an information disclosure vulnerability.
Advisories
No advisories yet.
Fixes
Solution
No solution has been reported as yet.
Workaround
No workaround given by the vendor.
References
History
Mon, 14 Sep 2026 12:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Inadequate access control in Hiperdino’s REST v1.0 API. The public endpoint ‘customer/check’ could allow an authenticated attacker to enter a telephone number or an email address. When the value entered belongs to a registered customer, the service returns the associated information (email address and telephone number). No authentication is required beyond a static bearer token, and there is no rate limiting or generic error handling. Successful exploitation of this vulnerability could allow a remote attacker to enumerate a user’s contact details, although this would require obtaining a valid static bearer token, constituting an information disclosure vulnerability. | |
| Title | Inadequate access control in the Hiperdino REST API | |
| First Time appeared |
Hiperdino
Hiperdino rest Api |
|
| Weaknesses | CWE-284 | |
| CPEs | cpe:2.3:a:hiperdino:rest_api:1.0:*:*:*:*:*:*:* | |
| Vendors & Products |
Hiperdino
Hiperdino rest Api |
|
| References |
| |
| Metrics |
cvssV4_0
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: INCIBE
Published:
Updated: 2026-09-14T14:18:26.668Z
Reserved: 2026-06-15T09:37:00.376Z
Link: CVE-2026-12258
No data.
Status : Received
Published: 2026-09-14T13:17:33.290
Modified: 2026-09-14T15:17:04.153
Link: CVE-2026-12258
No data.
OpenCVE Enrichment
No data.
Weaknesses