Junglewise Threat Intelligence

CVE-2025-65784: Hubert Hub 2.0 IDOR in API endpoints

CVE-2025-65784 · Severity: medium · CVSS 6.5 · Published 2026-01-13

Executive brief

Hubert Hub 2.0, a platform used for property management and resident services, contains a security flaw that allows registered users to view the private information of other residents. By making minor changes to web requests, an attacker can access sensitive data such as full names, email addresses, and national identification numbers (CPF). This could lead to significant privacy violations and the exposure of customer data to unauthorized parties.

Technical details

Hubert Hub 2.0 version 1.27.3 for iOS, Android, and Web contains a Broken Object Level Authorization (BOLA/IDOR) vulnerability. The flaw exists in the API endpoints, specifically within /api/v1/unidades/ and related enderecamento queries, where the application fails to validate if the requesting user has permission to access the requested object ID. An authenticated attacker with low-level privileges can manipulate these identifiers to retrieve sensitive records, including national ID (CPF), names, and email addresses. Although CISA-ADP categorized this as SSRF (CWE-918), the technical evidence and PoC confirm it is an IDOR/BOLA (CWE-639) issue. No patch has been explicitly confirmed in the advisory.

Affected products

  • Hubert Imoveis e Administracao Ltda Hub 2.0 1.27.3

Timeline

  • 2025-11: other: Vulnerability discovered by Carlos Artmann
  • 2026-01-13: disclosed: CVE published

References