CRITICAL
Hiperdino
CVE published 2026-09-14
CVE-2026-12258
CVE-2026-12258 is an information disclosure vulnerability in Hiperdino's REST v1.0 API. The public endpoint 'customer/check' allows an authenticated attacker to enter a telephone number or email address and retrieve associated customer information if the value belongs to a registered customer. This requires a valid static bearer token but no further authentication, and there is no rate limiting or generic [truncated]