CVE-2026-4262

Incorrect authorization in HiJiffy Chatbot

Title source: cna

Description

Vulnerability of incorrect authorization in HiJiffy Chatbot allows an attacker to download private messages from other users via the parameter 'ID' in '/api/v1/download/<ID>/'.

Scores

EPSS 0.0004
EPSS Percentile 12.4%

Details

CWE
CWE-863
Status published
Products (1)
HiJiffy/HiJiffy Chatbot all versions
Published Mar 26, 2026
Tracked Since Mar 26, 2026