CVE-2026-24898: Unauthenticated Api Login Response Disclosure
Unauthenticated PHP endpoint (sets $ignoreAuth = true to bypass auth) echoes the raw return value of an API login call directly as JSON. Login responses commonly contain bearer tokens, session credentials, or other secrets. Filter the response before echoing — return only non-sensitive status fields such as {"success": true} or {"error": "..."} — and add a f
greprules fetch cve-2026-24898-unauthenticated-api-login-response-disclosure --engine opengrepDescription
Unauthenticated PHP endpoint (sets $ignoreAuth = true to bypass auth) echoes the raw return value of an API login call directly as JSON. Login responses commonly contain bearer tokens, session credentials, or other secrets. Filter the response before echoing — return only non-sensitive status fields such as {"success": true} or {"error": "..."} — and add a f
Community feedback
0 rule-level signals from signed-in users.
- Useful reports
- 0
- Context false positives
- 0
- Metadata suggestions
- 0
Contextual precision
Aggregated from approved scan feedback. False-positive reports describe observed scan contexts, not a global rule verdict.
- Findings observed
- 0
- Projects
- 0
- Reporters
- 0
Precision details are collecting more signed-in reports before verdict counts or ratios are emphasized.
No approved finding verdicts yet.
No scan diagnostics reported yet.