CVE-2026-4263

Publication date

2026-03-26 09:12:45

Family

INCIBE

State

PUBLISHED

Description

Vulnerability of incorrect authorization in HiJiffy Chatbot allows an attacker to download private messages from other users via the parameter  visitor in /api/v1/webchat/message.