An automotive lead platform keyed its records to a simple sequential number with no login, letting anyone read several million car buyers' names, home addresses, phones and emails, and silently overwrite their stored contact details.
Jun 30, 2026A single order route was left open while every sibling required a login, exposing well over a million B2B orders with full customer contact details, shipping and billing addresses, invoices and pricing, enumerable by counting.
Jun 30, 2026A healthcare booking backend left key routes open, letting anyone read real patients' names, birth dates, contact details and reason for visit, and even write records, across many thousands of medical practices with no login.
Jun 30, 2026A group-purchase checkout trusted the price sent by the browser when creating a real payment page, letting an unauthenticated buyer turn a $64,500 order into a $100 charge.
Jun 30, 2026A staff-only internal admin console accepted an ordinary customer's login token, and one endpoint skipped its tenant check, exposing other customers' jobs, internal cloud storage paths and staff details.
Jun 30, 2026A news publisher's first-party content feed returned the complete body of premium, subscriber-only articles, and some not-yet-published pieces, to any anonymous client with no login at all.
Jun 28, 2026A missing ownership check on a commerce platform's permission-approval call let a private app's own developer grant itself full read and write access to a merchant's customer and staff data, self-approving from an unrelated free store.
Jun 24, 2026A broken access-control flaw let any ordinary account on a corporate travel platform create a roleless guest login that could read a directory of more than 800,000 travellers, in bulk or by targeted name and email lookup.
Jun 24, 2026Remote-fetch SQL functions attached the database provider's own production cloud identity to tenant-controlled requests, letting a free-tier customer steal live Google and Microsoft cloud tokens and map the internal cluster.
Jun 23, 2026A free supplier account on a travel marketplace could read any other supplier's bookings by typing a reference number, harvesting traveller names and trip data with no ownership check.
Jun 22, 2026