Junglewise Threat Intelligence

CVE-2026-38568: StratonWebDesigners HireFlow IDOR in candidate and interview endpoints

CVE-2026-38568 · Severity: info · CVSS 8.1 · Published 2026-05-11

Technologies: StratonWebDesigners HireFlow. Vendors: StratonWebDesigners.

Executive brief

HireFlow, a web-based interview management system, contains a security flaw that allows any registered user to view sensitive information belonging to others. By simply changing the ID number in the web address, an attacker can access private candidate profiles and interview notes. This could lead to a full data breach of all recruitment records within the organization.

Technical details

HireFlow v1.2 is vulnerable to Insecure Direct Object Reference (IDOR) due to incorrect access control in the `candidate_detail()` and `interview_detail()` functions within `app.py`. The application fails to perform object-level authorization checks on the `/candidate/<id>` and `/interview/<id>` endpoints, relying solely on user-supplied integer IDs to fetch records. An authenticated attacker can perform horizontal privilege escalation by iterating through sequential IDs to view all candidate data and interview notes in the database. The vulnerability is addressed in version 1.3.

Affected products

  • StratonWebDesigners HireFlow 1.2

Timeline

  • 2026-05-11: disclosed
  • 2026-05-11: advisory: NVD publication date
  • 2026-05-11: patched: Patch available in v1.3

References

Related threats