CVE-2026-28217
IDOR in Hoppscotch GraphQL Allows Unauthorized Collection Access
Publication date: 2026-02-26
Last updated on: 2026-02-27
Assigner: GitHub, Inc.
Description
Description
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| hoppscotch | hoppscotch | to 2026.2.0 (exc) |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-639 | The system's authorization functionality does not prevent one user from gaining access to another user's data or record by modifying the key value identifying the data. |
| CWE-862 | The product does not perform an authorization check when an actor attempts to access a resource or perform an action. |
Attack-Flow Graph
AI Powered Q&A
What immediate steps should I take to mitigate this vulnerability?
To mitigate this vulnerability, upgrade hoppscotch to version 2026.2.0 or later, as this version fixes the issue by adding the missing authorization check.
Can you explain this vulnerability to me?
This vulnerability is an Insecure Direct Object Reference (IDOR) in the hoppscotch API development ecosystem prior to version 2026.2.0. Specifically, the `userCollection` GraphQL query accepts any collection ID and returns the full collection dataβincluding sensitive information like HTTP request headers and potentially secretsβto any authenticated user without verifying ownership of the collection. This missing authorization check allows users to access collections they do not own.
How can this vulnerability impact me? :
The vulnerability can lead to unauthorized disclosure of sensitive data. Since the `userCollection` query returns full collection data including HTTP request headers and potentially secrets, an attacker or unauthorized user with valid authentication could access confidential information belonging to other users. This could compromise security by exposing API keys, tokens, or other sensitive request data.
How does this vulnerability affect compliance with common standards and regulations (like GDPR, HIPAA)?:
I don't know
How can this vulnerability be detected on my network or system? Can you suggest some commands?
I don't know