Analysis and contextual insights are available on OpenCVE Cloud.
Vendor Solution
HiJiffy recommends updating to the latest available version.
Tracking
Sign in to view the affected projects.
No advisories yet.
Thu, 26 Mar 2026 14:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 26 Mar 2026 09:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Vulnerability of incorrect authorization in HiJiffy Chatbot allows an attacker to download private messages from other users via the parameter 'ID' in '/api/v1/download/<ID>/'. | |
| Title | Incorrect authorization in HiJiffy Chatbot | |
| First Time appeared |
Hijiffy
Hijiffy hijiffy Chatbot |
|
| Weaknesses | CWE-863 | |
| CPEs | cpe:2.3:a:hijiffy:hijiffy_chatbot:all_versions:*:*:*:*:*:*:* | |
| Vendors & Products |
Hijiffy
Hijiffy hijiffy Chatbot |
|
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: INCIBE
Published:
Updated: 2026-03-26T14:06:16.836Z
Reserved: 2026-03-16T11:59:56.946Z
Link: CVE-2026-4262
Updated: 2026-03-26T14:06:06.102Z
Status : Awaiting Analysis
Published: 2026-03-26T10:16:25.780
Modified: 2026-03-26T15:13:15.790
Link: CVE-2026-4262
No data.
OpenCVE Enrichment
Updated: 2026-03-27T08:36:20Z