Junglewise Threat Intelligence

CVE-2026-45248: Hedera Guardian authentication bypass in demo registered-users endpoint

CVE-2026-45248 · Severity: medium · CVSS 5.3 · Published 2026-05-14

Technologies: Hedera Guardian.

Executive brief

Hedera Guardian, an open-source solution for managing digital environmental assets, contains a security flaw that allows anyone to access a list of registered users without logging in. An attacker can exploit this to view sensitive account details, including usernames, system roles, and unique digital identifiers (DIDs). This exposure could lead to targeted phishing attacks or further unauthorized access to the system's policy management functions.

Technical details

An authentication bypass vulnerability exists in Hedera Guardian through version 3.5.1 due to a missing authentication guard on the 'GET /api/v1/demo/registered-users' endpoint (CWE-306). The root cause is the absence of the @Auth decorator in the api-gateway service, which is present on sibling endpoints. A remote, unauthenticated attacker can query this endpoint to obtain a JSON response containing usernames, Hedera Decentralized Identifiers (DIDs), parent registry DIDs, system roles, and policy role assignments for all users in the database. A fix has been proposed in the project's GitHub repository (Pull Request #6076) to apply the necessary permission guards.

Affected products

  • Hedera Guardian up to and including 3.5.1

Timeline

  • 2026-05-14: disclosed: Vulnerability disclosed and pull request created
  • 2026-05-14: advisory: Initial advisory published by VulnCheck
  • 2026-05-27: other: NVD record updated with CPE information

References