Inadequate access control in the Hiperdino REST API

Posted date 14/09/2026
Identificador
INCIBE-2026-628
Importance
5 - Critical
Affected Resources

Hiperdino REST API v1.0.

Description

INCIBE has coordinated the disclosure of a critical-severity vulnerability affecting the Hiperdino REST API, which acts as a bridge for carrying out actions automatically and in real time. The vulnerability was discovered by Jorge Ramos Santana.

This vulnerability has been assigned the following code, CVSS v4.0 base score, CVSS vector and CWE vulnerability type:

  • CVE-2026-12258: CVSS v4.0: 9.2 | CVSS AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:H/SI:N/SA:N | CWE-284
Solution

No solution has been reported as yet.

Detail

CVE-2026-12258: inadequate access control in Hiperdino’s REST v1.0 API. The public endpoint ‘customer/check’ could allow an authenticated attacker to enter a telephone number or an email address. When the value entered belongs to a registered customer, the service returns the associated information (email address and telephone number). No authentication is required beyond a static bearer token, and there is no rate limiting or generic error handling. Successful exploitation of this vulnerability could allow a remote attacker to enumerate a user’s contact details, although this would require obtaining a valid static bearer token, constituting an information disclosure vulnerability.

CVE
Identificador CVE Severidad Explotación Fabricante
CVE-2026-12258 Crítica No Hiperdino
References list
Etiquetas