PatchSiren

Hiperdino CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

CRITICAL Hiperdino CVE published 2026-09-14

CVE-2026-12258

CVE-2026-12258 is an information disclosure vulnerability in Hiperdino's REST v1.0 API. The public endpoint 'customer/check' allows an authenticated attacker to enter a telephone number or email address and retrieve associated customer information if the value belongs to a registered customer. This requires a valid static bearer token but no further authentication, and there is no rate limiting or generic [truncated]