CVE-2026-69189
Last modified
CVE-2026-69189 is a high-severity vulnerability rated 7.6/10 on the CVSS scale. Hoppscotch is an open source API development ecosystem. Prior to 2026.6.0, the team, teamMembers.user, RESTHistory, GQLHistory, currentRESTSession, currentGQLSession, environments, globalEnvironments, and settings GraphQL paths expose another workspace member's private User data, while toggleHistoryStarStatus and removeRequestFromHistory in the UserHistory service accept another user's history identifier without enforcing userUid ownership, allowing an authenticated workspace member to read private request history, session data, request contents, authorization headers, environment values, and settings and to modify or delete the victim's private history entries. EPSS estimates a 0.29% chance of exploitation in the next 30 days.
Description
Hoppscotch is an open source API development ecosystem. Prior to 2026.6.0, the team, teamMembers.user, RESTHistory, GQLHistory, currentRESTSession, currentGQLSession, environments, globalEnvironments, and settings GraphQL paths expose another workspace member's private User data, while toggleHistoryStarStatus and removeRequestFromHistory in the UserHistory service accept another user's history identifier without enforcing userUid ownership, allowing an authenticated workspace member to read private request history, session data, request contents, authorization headers, environment values, and settings and to modify or delete the victim's private history entries. This issue is fixed in version 2026.6.0.
Metrics
Weakness Enumeration
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| hoppscotch | hoppscotch | < 2026.6.0 |
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2026-69189?
How severe is CVE-2026-69189?
How do I fix CVE-2026-69189?
How Strix Helps
- Uncovering a hidden BOLA in Appsmith's snapshot logicStrix autonomously discovered a BOLA/IDOR vulnerability in Appsmith's snapshot deletion path.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-69160OpenList a file list program that supports multiple storage.…6.5
- CVE-2026-6918In Eclipse Open9J versions 0.21 to 0.58, a pre-authenticatio…7.5
- CVE-2026-69183Monkeytype is a minimalistic and customizable typing test. I…7.5
- CVE-2026-69184c-ares is an asynchronous resolver library. Prior to 1.34.7,…7.5
- CVE-2026-69185Socket.IO enables bidirectional and low-latency communicatio…7.5
- CVE-2026-69186c-ares is an asynchronous resolver library. Prior to 1.34.7,…5.3
- CVE-2026-6919Use after free in DevTools in Google Chrome prior to 147.0.7…9.6
- CVE-2026-69190Graylog is a free and open log management platform. From 6.3…6.3
- CVE-2026-69192ip-address is a library for parsing and manipulating IPv4 an…7.7
- CVE-2026-69197Umbraco is an ASP.NET CMS. Prior to 13.15.1, 17.5.3, and 18.…8.7
- CVE-2026-69198ip-address is a library for parsing and manipulating IPv4 an…6.9
- CVE-2026-6920Out of bounds read in GPU in Google Chrome on Android prior …9.6
Are you affected by CVE-2026-69189?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
