PT-2026-22212 · Unknown · Hoppscotch

Bugbunny-Research

·

Published

2026-02-26

·

Updated

2026-02-27

·

CVE-2026-28217

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions hoppscotch versions prior to 2026.2.0
Description The userCollection GraphQL query in hoppscotch does not verify ownership before returning collection data, including potentially sensitive information like HTTP requests and headers, to authenticated users. This is an Insecure Direct Object Reference (IDOR) issue stemming from a missing authorization check. The query accepts an arbitrary collection ID and returns the full collection data to any authenticated user, regardless of ownership.
Recommendations Update to version 2026.2.0 or later.

Exploit

Fix

Missing Authorization

IDOR

Weakness Enumeration

Related Identifiers

CVE-2026-28217
GHSA-M5PG-R4JP-QQ75

Affected Products

Hoppscotch