CVE-2026-28216Disclosure(hoppscotch / hoppscotch)

LOWCVSS 8.3 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

hoppscotch is an open source API development ecosystem. Prior to version 2026.2.0, any logged-in user can read, modify or delete another user's personal environment by ID. `user-environments.resolver.ts:82-109`, `updateUserEnvironment` mutation uses `@UseGuards(GqlAuthGuard)` but is missing the `@GqlUser()` decorator entirely. The user's identity is never extracted, so the service receives only the environment ID and performs a `prisma.userEnvironment.update({ where: { id } })` without any ownership filter. `deleteUserEnvironment` does extract the user but the service only uses the UID to check if the target is a global environment. Actual delete query uses WHERE { id } without AND userUid. hoppscotch environments store API keys, auth tokens and secrets used in API requests. An authenticated attacker who obtains another user's environment ID can read their secrets, replace them with malicious values or delete them entirely. The environment ID format is CUID, which limits mass exploitation but insider threat and combined info leak scenarios are realistic. Version 2026.2.0 fixes the issue.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-639

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

NONE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • hoppscotch

Threat summary

  • 4 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 4 signals
  • Disclosure: 4 classified signals
  • Peaked 2d ago at 2 mentions (2026-02-26); latest day: 1
  • 4 total mentions across 3 days

Affected systems

Vendors
Products
hoppscotch

Deep dive

Activity timeline4 mentions / 3d
01122Mentions · 2026-02-26: 2Mentions · 2026-02-27: 1Mentions · 2026-03-03: 1Technical Details · 2026-02-26: 2Technical Details · 2026-02-27: 1Technical Details · 2026-03-03: 102-2602-2703-03
Signal classification1 categories
Disclosure
4100.0%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-02-262
Disclosure2
2026-02-271
Disclosure1
2026-03-031
Disclosure1
Full discourse4 posts
  • CVE@CVEnew
    Disclosure

    CVE-2026-28216 hoppscotch is an open source API development ecosystem. Prior to version 2026.2.0, any logged-in user can read, modify or delete another user's personal environment b… https://www.cve.org/CVERecord?id=CVE-2026-28216

    Post summary

    CVE-2026-28216 impacts hoppscotch by allowing a logged‑in user to read, modify or delete another user's personal environment prior to version 2026.2.0. No PoC, exploit, patch, or active exploitation details are provided.

    00010146
    56.6K followersView on X
  • CRAC Learning - Tech@cracbot
    Disclosure

    CVE-2026-28216 (CVSS:8.3, HIGH) is Analyzed. hoppscotch is an open source API development ecosystem. Prior to version 2026.2.0, any logged-in user can read, modify o..https://nvd.nist.gov/vuln/detail/CVE-2026-28216 #cybersecurityawareness #cybersecurity #CVE #infosec #hacker #nvd #mitre

    Post summary

    The post announces CVE-2026-28216, a high‑severity vulnerability in hoppscotch that allows logged‑in users to read and modify data before version 2026.2.0, with no mention of patches or active exploitation.

    0000034
    173 followersView on X
  • CVETodo@CveTodo
    Disclosure

    CVE-2026-28216 pertains to a critical security flaw in Hoppscotch, an open-source API development ecosystem. Prior to version 2026.2.0, the application improperly handled user environment access controls, allowing any authenticated user to read, modify, or delete another user's environment data by simply knowing the environment ID. This flaw stems from incomplete authorization checks in the code responsible for environment management, specifically in the `user-environments.resolver.ts` file. #Cybersecurity #CVE #HighSeverity #SecurityAlert #RemoteCodeExecution https://cvetodo.com/cve/CVE-2026-28216

    Post summary

    The text announces a critical CVE-2026-28216 in Hoppscotch, detailing how authenticated users can access others’ environments due to missing authorization checks, without any mention of PoC, exploit code, or active exploitation.

    0000039
    20 followersView on X
  • The Hacker Wire@TheHackerWire
    Disclosure

    🟠 CVE-2026-28216 - High hoppscotch is an open source API development ecosystem. Prior to version 2026.2.0, any logged-in user can read, modify or delete another user's personal environment by ID. `user-environments.... https://www.thehackerwire.com/vulnerability/CVE-2026-28216/ https://t.co/1pvghO0MaK

    Post summary

    The tweet announces the high‑severity CVE‑2026‑28216 affecting hoppscotch, describing its read/write/delete privilege escalation flaw before version 2026.2.0.

    0000044
    115 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Apphoppscotchhoppscotch---

Explore more