PT-2026-22212 · Unknown · Hoppscotch
Bugbunny-Research
·
Published
2026-02-26
·
Updated
2026-02-27
·
CVE-2026-28217
CVSS v3.1
6.5
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
hoppscotch versions prior to 2026.2.0
Description
The
userCollection GraphQL query in hoppscotch does not verify ownership before returning collection data, including potentially sensitive information like HTTP requests and headers, to authenticated users. This is an Insecure Direct Object Reference (IDOR) issue stemming from a missing authorization check. The query accepts an arbitrary collection ID and returns the full collection data to any authenticated user, regardless of ownership.Recommendations
Update to version 2026.2.0 or later.
Exploit
Fix
Missing Authorization
IDOR
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Hoppscotch