CVE-2026-28215Disclosure(hoppscotch / hoppscotch)

LOWCVSS 9.1 · CRITICAL

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch hoppscotch hoppscotch systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

hoppscotch is an open source API development ecosystem. Prior to version 2026.2.0, an unauthenticated attacker can overwrite the entire infrastructure configuration of a self-hosted Hoppscotch instance including OAuth provider credentials and SMTP settings by sending a single HTTP POST request with no authentication. The endpoint POST /v1/onboarding/config has no authentication guard and performs no check on whether onboarding was already completed. A successful exploit allows the attacker to replace the instance's Google/GitHub/Microsoft OAuth application credentials with their own, causing all subsequent user logins via SSO to authenticate against the attacker's OAuth app. The attacker captures OAuth tokens and email addresses of every user who logs in after the exploit. Additionally, the endpoint returns a recovery token that can be used to read all stored secrets in plaintext, including SMTP passwords and any other configured credentials. Version 2026.2.0 fixes the issue.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-284CWE-287

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • hoppscotch

Threat summary

  • Patch or workaround signal is available
  • 9 mentions across 7 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 6 signals
  • Disclosure: 5 classified signals
  • General: 2 classified signals
  • Peaked 6d ago at 2 mentions (2026-02-26); latest day: 1
  • 9 total mentions across 7 days

Affected systems

Vendors
Products
hoppscotch

Deep dive

Activity timeline9 mentions / 7d
01122Mentions · 2026-02-26: 2Mentions · 2026-02-27: 2Mentions · 2026-02-28: 1Mentions · 2026-03-03: 1Mentions · 2026-05-13: 1Mentions · 2026-05-14: 1Mentions · 2026-08-27: 1Patch / Workaround · 2026-02-28: 1Technical Details · 2026-02-26: 2Technical Details · 2026-02-27: 2Technical Details · 2026-02-28: 1Technical Details · 2026-03-03: 102-2602-2702-2803-0305-1305-1408-27
Signal classification3 categories
Disclosure
555.6%
Patch
222.2%
General
222.2%
Referenced assets7 URLs
Classification over time
DateTotalLabels
2026-02-262
Disclosure2
2026-02-272
Disclosure2
2026-02-281
Patch1
2026-03-031
Disclosure1
2026-05-131
Patch1
2026-05-141
General1
2026-08-271
General1
Full discourse9 posts
  • BugBunny.ai - Continuous AI Pentesting System@BugBunny_ai
    General

    66 CVE-2025-58434 CVE-2025-59057 CVE-2025-59790 CVE-2025-59792 CVE-2025-61622 CVE-2025-61686 CVE-2025-64756 CVE-2026-21884 CVE-2026-22807 CVE-2026-23630 CVE-2026-27471 CVE-2026-27806 CVE-2026-27955 CVE-2026-28215 CVE-2026-28217 CVE-2026-28351 CVE-2026-28361 CVE-2026-28384 CVE-2026-28396 CVE-2026-28398 CVE-2026-28444 CVE-2026-28445 CVE-2026-29093 CVE-2026-30973 CVE-2026-31888 CVE-2026-33016 CVE-2026-33037 CVE-2026-33038 CVE-2026-33039 CVE-2026-3351 CVE-2026-34037 CVE-2026-34158 CVE-2026-34167 CVE-2026-34170 CVE-2026-34171 CVE-2026-34198 CVE-2026-34532 CVE-2026-34573 CVE-2026-34574 CVE-2026-34595 CVE-2026-34746 CVE-2026-34748 CVE-2026-34749 CVE-2026-34750 CVE-2026-34972 CVE-2026-35214 CVE-2026-35412 CVE-2026-35413 CVE-2026-35441 CVE-2026-40165 CVE-2026-40293 CVE-2026-40302 CVE-2026-40304 CVE-2026-40454 CVE-2026-40914 CVE-2026-41131 CVE-2026-41590 CVE-2026-42883 CVE-2026-42884 CVE-2026-42885 CVE-2026-42886 CVE-2026-43888 CVE-2026-43889 CVE-2026-43998 CVE-2026-43999 CVE-2026-4800

    Post summary

    The content is a simple enumeration of CVE identifiers with no accompanying details, indicators, or analysis.

    2176862729382.1K
    3.1K followersView on X
  • BugBunny.ai - Continuous AI Pentesting System@BugBunny_ai
    General

    108 CVE-2025-58434 CVE-2025-59057 CVE-2025-59343 CVE-2025-59790 CVE-2025-59792 CVE-2025-61622 CVE-2025-61686 CVE-2025-62228 CVE-2025-62232 CVE-2025-64756 CVE-2026-21884 CVE-2026-22706 CVE-2026-22807 CVE-2026-23630 CVE-2026-24015 CVE-2026-24899 CVE-2026-27471 CVE-2026-27806 CVE-2026-27955 CVE-2026-28215 CVE-2026-28217 CVE-2026-28351 CVE-2026-28361 CVE-2026-28384 CVE-2026-28396 CVE-2026-28398 CVE-2026-28444 CVE-2026-28445 CVE-2026-29093 CVE-2026-30973 CVE-2026-31888 CVE-2026-33016 CVE-2026-33037 CVE-2026-33038 CVE-2026-33039 CVE-2026-33264 CVE-2026-33413 CVE-2026-3351 CVE-2026-34037 CVE-2026-34158 CVE-2026-34167 CVE-2026-34170 CVE-2026-34171 CVE-2026-34198 CVE-2026-34532 CVE-2026-34573 CVE-2026-34574 CVE-2026-34595 CVE-2026-34746 CVE-2026-34748 CVE-2026-34749 CVE-2026-34750 CVE-2026-34972 CVE-2026-35214 CVE-2026-35412 CVE-2026-35413 CVE-2026-35441 CVE-2026-40006 CVE-2026-40007 CVE-2026-40009 CVE-2026-40165 CVE-2026-40293 CVE-2026-40302 CVE-2026-40304 CVE-2026-40452 CVE-2026-40454 CVE-2026-40914 CVE-2026-41131 CVE-2026-41590 CVE-2026-42275 CVE-2026-42883 CVE-2026-42884 CVE-2026-42885 CVE-2026-42886 CVE-2026-43888 CVE-2026-43889 CVE-2026-43998 CVE-2026-43999 CVE-2026-44247 CVE-2026-44309 CVE-2026-44310 CVE-2026-44442 CVE-2026-44446 CVE-2026-44705 CVE-2026-44947 CVE-2026-45022 CVE-2026-45090 CVE-2026-45720 CVE-2026-45723 CVE-2026-45726 CVE-2026-46553 CVE-2026-46554 CVE-2026-47733 CVE-2026-4800 CVE-2026-48978 CVE-2026-49478 CVE-2026-50285 CVE-2026-52808 CVE-2026-52809 CVE-2026-53926 CVE-2026-53928 CVE-2026-53929 CVE-2026-53930 CVE-2026-56842 CVE-2026-60076 CVE-2026-60077 CVE-2026-75605 CVE-2026-9103

    Post summary

    The post merely enumerates a large set of CVE identifiers, lacking any additional context such as proof of concept, exploit code, active exploitation reports, or mitigation information.

    30124138.4K
    4.0K followersView on X
  • CVE@CVEnew
    Patch

    CVE-2026-44478 hoppscotch is an open source API development ecosystem. The fix for CVE-2026-28215 in version 2026.2.0 addresses the unauthenticated POST /v1/onboarding/config endpoi… https://www.cve.org/CVERecord?id=CVE-2026-44478

    Post summary

    The note references CVE‑2026‑44478 but only cites a patch for a different CVE (2026‑28215) and provides no PoC, exploitation, or detailed vulnerability information.

    0000076
    57.5K followersView on X
  • CRAC Learning - Tech@cracbot
    Disclosure

    CVE-2026-28215 (CVSS:9.1, CRITICAL) is Analyzed. hoppscotch is an open source API development ecosystem. Prior to version 2026.2.0, an unauthenticated attacker can overw..https://nvd.nist.gov/vuln/detail/CVE-2026-28215 #cybersecurityawareness #cybersecurity #CVE #infosec #hacker #nvd #mitre

    Post summary

    The post announces CVE-2026-28215, a critical vulnerability in hoppscotch that allows unauthenticated attackers to overwrite data, but provides no PoC, exploit, or patch details.

    0000034
    173 followersView on X
  • PulsePatch.io@pulsepatchio
    Patch

    A critical unauthenticated onboarding config takeover vulnerability (CVE-2026-28215) affects `hoppscotch`. Updating to the fixed version is advised to prevent unauthorized configuration changes. #hoppscotch #infosec #vulnerability https://www.pulsepatch.io/posts/cve-2026-28215-hoppscotch-unauthenticated-onboarding-takeover

    Post summary

    The post announces CVE-2026-28215, a critical unauthenticated onboarding config takeover in hoppscotch, and advises updating to the fixed version to mitigate the risk.

    0000050
    1 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-28215 hoppscotch is an open source API development ecosystem. Prior to version 2026.2.0, an unauthenticated attacker can overwrite the entire infrastructure configuration o… https://www.cve.org/CVERecord?id=CVE-2026-28215

    Post summary

    The text announces CVE‑2026‑28215 for Hoppscotch, describing a critical configuration overwrite flaw affecting versions prior to 2026.2.0, but provides no exploit code, PoC, patch, or evidence of active exploitation.

    00000147
    56.6K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-28215 Unauthenticated Configuration Overwrite in Hoppscotch Prior to 2026.2.0 https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-28215

    Post summary

    A CVE-2026-28215 vulnerability, an unauthenticated configuration overwrite in Hoppscotch prior to version 2026.2.0, has been disclosed. No PoC, exploit, active exploitation, patch, or false positive information is provided.

    0000029
    4.0K followersView on X
  • CVEFind.com@CveFindCom
    Disclosure

    [CVE-2026-28215: CRITICAL] Hoppscotch, an API development ecosystem, had a critical security flaw allowing unauthenticated attackers to take over infrastructure, compromising OAuth and SMTP settings. Update ...#cve,CVE-2026-28215,#cybersecurity https://cvefind.com/CVE-2026-28215

    Post summary

    CVE‑2026‑28215 is a critical flaw in Hoppscotch that permits unauthenticated attackers to take over infrastructure, compromising OAuth and SMTP settings, with no evidence of active exploitation or a patch.

    0000051
    585 followersView on X
  • CVETodo@CveTodo
    Disclosure

    The core issue is that this endpoint: - Does not require authentication. - Performs no check to determine if onboarding has already been completed. - Returns a recovery token that can be used to access stored secrets in plaintext. #Cybersecurity #CVE #CriticalCVE #CriticalVulnerability #RemoteCodeExecution #Microsoft #Google https://cvetodo.com/cve/CVE-2026-28215

    Post summary

    The CVE-2026-28215 vulnerability allows unauthenticated access to a recovery token that exposes stored secrets in plaintext, due to missing authentication and onboarding checks.

    0000029
    20 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Apphoppscotchhoppscotch---

Explore more