
🚨*CVE* CVE-2026-38568 HireFlow v1.2 is vulnerable to Incorrect Access Control. The application does not enforce object-level authorization on the /candidate/
Post summary
A new CVE (CVE-2026-38568) has been identified in HireFlow v1.2, highlighting an incorrect access control issue where object‑level authorization is not enforced on the /candidate/ endpoint.

