CVE-2026-12258: Inadequate access control in the Hiperdino REST API

Published Sep 14, 2026
·
Updated

Inadequate access control in Hiperdino’s REST v1.0 API. The public endpoint ‘customer/check’ could allow an authenticated attacker to enter a telephone number or an email address. When the value entered belongs to a registered customer, the service returns the associated information (email address and telephone number). No authentication is required beyond a static bearer token, and there is no rate limiting or generic error handling. Successful exploitation of this vulnerability could allow a remote attacker to enumerate a user’s contact details, although this would require obtaining a valid static bearer token, constituting an information disclosure vulnerability.

Affected Software

1 affected component
Hiperdino REST API=v1.0

Event History

Sep 14, 2026
CVE Published
via MITRE·12:11 PM
Data Sourced
via MITRE·12:11 PM
RemedyDescriptionWeakness

Frequently Asked Questions

1

What does an attacker need to exploit this issue?

The attacker needs a valid static bearer token to call the public customer/check endpoint. With that token, they can submit telephone numbers or email addresses and identify registered customers.

2

What information can be disclosed?

For values associated with registered customers, the API returns the customer’s email address and telephone number. The lack of generic error handling can also help distinguish registered values from non-registered ones.

3

Why is large-scale enumeration a concern?

The endpoint has no rate limiting, allowing repeated requests with candidate email addresses or telephone numbers. This can enable remote enumeration of customer contact details by an attacker who has obtained a valid bearer token.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203