Back to Blog
CVE-2026-50160: Hoppscotch API Platform — Unauthenticated Server Takeover (June 2026)
vulnerabilities

CVE-2026-50160: Hoppscotch API Platform — Unauthenticated Server Takeover (June 2026)

breachwire TeamJun 26, 20262 min read

CVE-2026-50160 — Hoppscotch API Platform

CVE-2026-50160 is a critical unauthenticated vulnerability in self-hosted Hoppscotch API Platform deployments. The flaw allows remote attackers to inject sensitive configuration keys, including JWT and session secrets, via a single HTTP request. This results in full server compromise and persistent unauthorized access, regardless of password resets. No authentication is required, and the vulnerability is trivial to exploit. CVSS score is critical; active exploitation status is not yet confirmed but should be assumed imminent.

Attack Vector

Attackers exploit CVE-2026-50160 by sending a crafted HTTP request to the Hoppscotch server, overwriting core configuration keys such as JWT and session secrets. This manipulation grants the attacker control over authentication and session management, enabling persistent access and the ability to bypass future credential changes. No prior access or credentials are needed. The attack can be performed remotely against any exposed self-hosted Hoppscotch instance.

Who Is at Risk

All organizations running self-hosted instances of the Hoppscotch API Platform are at immediate risk. Cloud-hosted (SaaS) versions are not affected. Hoppscotch is the confirmed affected vendor. Any internet-exposed, unpatched self-hosted deployment is vulnerable to full takeover.

Patch & Mitigate

  • Patch: Apply the latest Hoppscotch security update immediately. If no patch is available, restrict external access to the server until remediation is possible.
  • Workaround: Limit network exposure by firewalling the Hoppscotch instance and disabling public access.
  • Detect: Review server logs for unauthorized configuration changes, unexpected JWT/session secret updates, and anomalous HTTP requests to configuration endpoints.

MITRE ATT&CK

  • TA0001 — Initial Access: Attackers gain access without authentication via exposed HTTP endpoints.
  • TA0006 — Credential Access: Overwriting JWT/session secrets enables control over authentication mechanisms.
  • TA0008 — Lateral Movement: Full server compromise may allow pivoting to other systems or services.

Source: https://thehackernews.com/2026/06/threatsday-bulletin-smart-tv-proxyware.html

Start Your 14-Day Free Trial

Get curated cyber intelligence delivered to your inbox every morning at 6 AM. No credit card required.

Get Started Free
Share this article: