Executive brief
The Superior Court of California's Hearing Reminder Service, which provides automated notifications for court dates, contains a security flaw in its web interface. An unauthorized individual could access an unprotected API endpoint to view court reminder records. This could lead to the exposure of sensitive personal information related to court proceedings.
Technical details
The Hearing Reminder Service (HRS) web application fails to implement proper authentication checks on a specific API endpoint (CWE-306). A remote, unauthenticated attacker can query this endpoint over the network to retrieve court reminder records. These records contain sensitive data intended for specific participants. The vulnerability was addressed in an update released on April 28, 2026; versions prior to this date are considered affected.
Affected products
- Superior Court of California, County of Los Angeles Hearing Reminder Service Versions prior to 2026-04-28
Timeline
- 2026-04-28: patched: Vendor released a fix for the service.
- 2026-07-09: disclosed: CVE published to the NVD.