Hi.Events through 1.9.0 public check-in list endpoints use short_id as sole access control, allowing unauthenticated access to retrieve full attendee lists including emails and personal information. Attackers with knowledge of the short_id can call GET /api/public/check-in-lists/{short_id}/attendees to read attendee data and create or delete check-in records without authentication.
References
Configurations
No configuration.
History
No history.
Information
Published : 2026-06-29 18:16
Updated : 2026-07-14 22:17
NVD link : CVE-2026-57960
Mitre link : CVE-2026-57960
CVE.ORG link : CVE-2026-57960
JSON object : View
Products Affected
No product.
CWE
CWE-359
Exposure of Private Personal Information to an Unauthorized Actor
