critical Millions of car-buyer leads read and rewritten, no login

Enumerable Lead ID Exposes Millions of Car-Buyer Records and Lets Anyone Overwrite Their Contact Details

An automotive lead platform keyed its records to a simple sequential number with no login, letting anyone read several million car buyers' names, home addresses, phones and emails, and silently overwrite their stored contact details.

Jun 30, 2026
Web APIIDORPII
critical Entire B2B order book, no login

One Unauthenticated Route Exposes an Entire B2B Order Book

A single order route was left open while every sibling required a login, exposing well over a million B2B orders with full customer contact details, shipping and billing addresses, invoices and pricing, enumerable by counting.

Jun 30, 2026
Web APIIDORPII
critical Patient health data read and write, no login

Unauthenticated Booking API Exposes Patient Health Data Across Thousands of Practices

A healthcare booking backend left key routes open, letting anyone read real patients' names, birth dates, contact details and reason for visit, and even write records, across many thousands of medical practices with no login.

Jun 30, 2026
Web APIAuth BypassPHI
high $64,500 order billed as $100

Client-Supplied Price Mints a Live Payment Token for Any Amount

A group-purchase checkout trusted the price sent by the browser when creating a real payment page, letting an unauthenticated buyer turn a $64,500 order into a $100 charge.

Jun 30, 2026
Web APIBusiness LogicPrice Manipulation
high Customer login reaches staff-only admin API

A Tenant Login Token Unlocks the Staff-Only Admin API and Other Tenants' Data

A staff-only internal admin console accepted an ordinary customer's login token, and one endpoint skipped its tenant check, exposing other customers' jobs, internal cloud storage paths and staff details.

Jun 30, 2026
Web APIAccess ControlMulti-Tenant
high Full paid articles served to anyone, no login

Unauthenticated Content Feed Leaks Full Paywalled and Unpublished Articles

A news publisher's first-party content feed returned the complete body of premium, subscriber-only articles, and some not-yet-published pieces, to any anonymous client with no login at all.

Jun 28, 2026
WebBroken Access ControlPaywall Bypass
high Rogue add-on developer self-grants full merchant access

Private-App Developer Self-Approves Its Own Permissions to Seize Merchant Data

A missing ownership check on a commerce platform's permission-approval call let a private app's own developer grant itself full read and write access to a merchant's customer and staff data, self-approving from an unrelated free store.

Jun 24, 2026
Web APIAccess ControlPrivilege Escalation
high 800,000+ travellers exposed to any free account

Self-Created Guest Account Reads a Travel Platform's Entire Traveller Directory

A broken access-control flaw let any ordinary account on a corporate travel platform create a roleless guest login that could read a directory of more than 800,000 travellers, in bulk or by targeted name and email lookup.

Jun 24, 2026
Web APIBroken Access ControlPII
critical Free-tier tenant steals provider's live cloud tokens

SQL Functions in a Cloud Database Console Steal the Provider's Production Cloud Credentials

Remote-fetch SQL functions attached the database provider's own production cloud identity to tenant-controlled requests, letting a free-tier customer steal live Google and Microsoft cloud tokens and map the internal cluster.

Jun 23, 2026
SQLSSRFCloud
high Free account harvests cross-supplier traveller data

Booking Reference Lookup Exposes Other Suppliers' Traveller Data

A free supplier account on a travel marketplace could read any other supplier's bookings by typing a reference number, harvesting traveller names and trip data with no ownership check.

Jun 22, 2026
WebIDORAccess Control