Junglewise Threat Intelligence

CVE-2026-61344: Superior Court of California Hearing Reminder Service missing authentication in API

CVE-2026-61344 · Severity: medium · CVSS 5.3 · Published 2026-07-09

Executive brief

The Superior Court of California's Hearing Reminder Service, which provides automated notifications for court dates, contains a security flaw in its web interface. An unauthorized individual could access an unprotected API endpoint to view court reminder records. This could lead to the exposure of sensitive personal information related to court proceedings.

Technical details

The Hearing Reminder Service (HRS) web application fails to implement proper authentication checks on a specific API endpoint (CWE-306). A remote, unauthenticated attacker can query this endpoint over the network to retrieve court reminder records. These records contain sensitive data intended for specific participants. The vulnerability was addressed in an update released on April 28, 2026; versions prior to this date are considered affected.

Affected products

  • Superior Court of California, County of Los Angeles Hearing Reminder Service Versions prior to 2026-04-28

Timeline

  • 2026-04-28: patched: Vendor released a fix for the service.
  • 2026-07-09: disclosed: CVE published to the NVD.

References