PT-2026-40829 · Unknown · Hoppscotch

Published

2026-05-13

·

Updated

2026-05-14

·

CVE-2026-44478

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions hoppscotch versions prior to 2026.4.0
Description An information disclosure issue exists where the 'GET /v1/onboarding/config' endpoint leaks infrastructure secrets in plaintext to unauthenticated users. This occurs specifically when the ONBOARDING RECOVERY TOKEN stored in the database is an empty string.
Recommendations Update to version 2026.4.0.

Exploit

Fix

Improper Authentication

Improper Access Control

Weakness Enumeration

Related Identifiers

CVE-2026-44478

Affected Products

Hoppscotch