Executive brief
The Johnson & Johnson Audit Tracking Management System (ATMS), a tool used to manage internal audits across various subsidiaries, contained a security flaw that allowed unauthorized access to sensitive information. An attacker could bypass the login screen to view confidential meeting minutes, transcripts, and employee data for multiple companies within the organization. This could lead to the exposure of proprietary business processes and internal compliance records.
Technical details
The Johnson & Johnson Audit Tracking Management System (ATMS) suffered from a failure to enforce server-side authentication (CWE-602). While the application used Microsoft Authentication Library (MSAL) on the frontend to redirect users to a login page, the underlying APIs—including those for retrieving user lists and session GUIDs—did not validate Bearer tokens or require authentication. An attacker could bypass the frontend redirect by modifying client-side code to spoof a logged-in state and manually requesting a session ID from the unauthenticated API. This granted full administrative access to the dashboard, allowing the retrieval of sensitive audit data, meeting transcripts, and a list of over 13,000 employees. The issue was resolved in April 2026 by implementing proper server-side authorization.
Affected products
- Johnson & Johnson Audit Tracking Management System (ATMS) before 2026-04-21
Timeline
- 2025-10-06: disclosed: Initial report to Johnson & Johnson
- 2026-04-21: patched: Vulnerability fixed in ATMS
- 2026-06-24: advisory: Researcher blog post published
- 2026-06-26: advisory: CVE published to NVD