← العودة للجدول
CVE-2026-28215
CVE-2026-28215 — hoppscotch is an open source API development ecosystem. Prior to version 2026.2.
📅 2026-02-26
🔴 Critical 🔥 No NVD APT Microsoft CVSS 9.1 🎯 EPSS 0.3%

📋 الوصف الكامل

hoppscotch is an open source API development ecosystem. Prior to version 2026.2.0, an unauthenticated attacker can overwrite the entire infrastructure configuration of a self-hosted Hoppscotch instance including OAuth provider credentials and SMTP settings by sending a single HTTP POST request with no authentication. The endpoint POST /v1/onboarding/config has no authentication guard and performs

💻 الأنظمة المتأثرة

hoppscotch is an

⚠️ نوع التهديد

APT

🔗 CVE ID

CVE-2026-28215

📡 المصدر

NVD

✅ الحلول والتخفيف

Update to v2026.2.

🔗 المصدر الأصلي ← 📘 NVD ← ⚡ CISA KEV ←