
CVE-2026-50160: Hoppscotch API Platform — Unauthenticated Server Takeover (June 2026)
CVE-2026-50160 — Hoppscotch API Platform
CVE-2026-50160 is a critical unauthenticated vulnerability in self-hosted Hoppscotch API Platform deployments. The flaw allows remote attackers to inject sensitive configuration keys, including JWT and session secrets, via a single HTTP request. This results in full server compromise and persistent unauthorized access, regardless of password resets. No authentication is required, and the vulnerability is trivial to exploit. CVSS score is critical; active exploitation status is not yet confirmed but should be assumed imminent.
Attack Vector
Attackers exploit CVE-2026-50160 by sending a crafted HTTP request to the Hoppscotch server, overwriting core configuration keys such as JWT and session secrets. This manipulation grants the attacker control over authentication and session management, enabling persistent access and the ability to bypass future credential changes. No prior access or credentials are needed. The attack can be performed remotely against any exposed self-hosted Hoppscotch instance.
Who Is at Risk
All organizations running self-hosted instances of the Hoppscotch API Platform are at immediate risk. Cloud-hosted (SaaS) versions are not affected. Hoppscotch is the confirmed affected vendor. Any internet-exposed, unpatched self-hosted deployment is vulnerable to full takeover.
Patch & Mitigate
- Patch: Apply the latest Hoppscotch security update immediately. If no patch is available, restrict external access to the server until remediation is possible.
- Workaround: Limit network exposure by firewalling the Hoppscotch instance and disabling public access.
- Detect: Review server logs for unauthorized configuration changes, unexpected JWT/session secret updates, and anomalous HTTP requests to configuration endpoints.
MITRE ATT&CK
- TA0001 — Initial Access: Attackers gain access without authentication via exposed HTTP endpoints.
- TA0006 — Credential Access: Overwriting JWT/session secrets enables control over authentication mechanisms.
- TA0008 — Lateral Movement: Full server compromise may allow pivoting to other systems or services.
Source: https://thehackernews.com/2026/06/threatsday-bulletin-smart-tv-proxyware.html
Start Your 14-Day Free Trial
Get curated cyber intelligence delivered to your inbox every morning at 6 AM. No credit card required.
Get Started Free

