CVE-2026-57912
Deferred
Deferred - Pending Action
Campus Recruiting Data Exposure Vulnerability
Publication date: 2026-06-26
Last updated on: 2026-06-26
Assigner: MITRE
Description
Description
Johnson & Johnson Campus Recruiting before 2025-10-31 allows viewing of data provided by recruited students, and notes entered about students by interviewers.
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| johnson_and_johnson | campus_recruiting | to 2025-10-31 (inc) |
| johnson_and_johnson | audit_tracking_management_system | to 2026-04-30 (inc) |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-602 | The product is composed of a server that relies on the client to implement a mechanism that is intended to protect the server. |