Inadequate access control in the Hiperdino REST API
Hiperdino REST API v1.0.
INCIBE has coordinated the disclosure of a critical-severity vulnerability affecting the Hiperdino REST API, which acts as a bridge for carrying out actions automatically and in real time. The vulnerability was discovered by Jorge Ramos Santana.
This vulnerability has been assigned the following code, CVSS v4.0 base score, CVSS vector and CWE vulnerability type:
- CVE-2026-12258: CVSS v4.0: 9.2 | CVSS AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:H/SI:N/SA:N | CWE-284
No solution has been reported as yet.
CVE-2026-12258: inadequate access control in Hiperdino’s REST v1.0 API. The public endpoint ‘customer/check’ could allow an authenticated attacker to enter a telephone number or an email address. When the value entered belongs to a registered customer, the service returns the associated information (email address and telephone number). No authentication is required beyond a static bearer token, and there is no rate limiting or generic error handling. Successful exploitation of this vulnerability could allow a remote attacker to enumerate a user’s contact details, although this would require obtaining a valid static bearer token, constituting an information disclosure vulnerability.
| Identificador CVE | Severidad | Explotación | Fabricante |
|---|---|---|---|
| CVE-2026-12258 | Crítica | No | Hiperdino |


