CVE-2026-24898: Unauthenticated Api Login Response Disclosure

Unauthenticated PHP endpoint (sets $ignoreAuth = true to bypass auth) echoes the raw return value of an API login call directly as JSON. Login responses commonly contain bearer tokens, session credentials, or other secrets. Filter the response before echoing — return only non-sensitive status fields such as {"success": true} or {"error": "..."} — and add a f

Provally CuratedPublic repositoryHighHigh confidenceVerifiedApache-2.0PHP
greprules fetch cve-2026-24898-unauthenticated-api-login-response-disclosure --engine opengrep

Description

Unauthenticated PHP endpoint (sets $ignoreAuth = true to bypass auth) echoes the raw return value of an API login call directly as JSON. Login responses commonly contain bearer tokens, session credentials, or other secrets. Filter the response before echoing — return only non-sensitive status fields such as {"success": true} or {"error": "..."} — and add a f