A public internal back-office sign-in client let any free account mint a high-privilege token and read and write a fitness platform's live subscription pricing catalog.
Jun 11, 2026A wildcard permission on a real-time messaging proxy let any self-registered account read live student behavior events from every classroom on an education platform, resolvable to real names.
Jun 11, 2026A missing access-control check let any free account turn raw identifiers into real student names and, after one teacher approval, take over a child's account.
Jun 11, 2026A third-party cookie-consent banner service accepted anonymous edits to its live banner config, which an insurer's site rendered into every page, executing attacker-controlled script for every visitor with no login and no interaction.
Jun 5, 2026A drivers-nearby endpoint on a chauffeur service's mobile backend returned the live, sub-meter GPS location of every active driver with no login, enabling bulk fleet mapping and continuous real-time tracking of any individual.
Jun 4, 2026A documented read-only reviewer role on a data integration platform could create and delete the self-hosted agents that route an account's data pipelines, including minting a live data-plane credential, because agent management was never governed by role-based access control.
Jun 4, 2026A misconfigured cloud identity provider let any low-privilege self-signup user overwrite the identity field the backend trusted, taking over any account, including a region administrator, with no victim interaction.
Jun 4, 2026A missing management-scope check on a group membership endpoint let a low-privilege group admin inject any same-org user into their group, then read and tamper with that user's private case files and plant a durable sharing policy for covert access.
Jun 3, 2026A path-normalization flaw let an unauthenticated attacker on the public internet defeat an address allowlist fronting an internal monitoring endpoint, exposing thousands of employee emails and the full B2B customer roster.
Jun 3, 2026An unauthenticated write to a content management system's visual page-design plugin planted a stored cross-site scripting payload that ran as a logged-in administrator, escalating to backoffice takeover and server-side code execution.
Jun 1, 2026