Back

MEDIUM

Incorrect authorization in HiJiffy Chatbot

Published Mar 26, 2026

Description

Vulnerability of incorrect authorization in HiJiffy Chatbot allows an attacker to download private messages from other users via the parameter  'visitor' in '/api/v1/webchat/message'.

Affected products

Remediation

Vendor solution

The vulnerabilities have been resolved by the HiJiffy team. Since the affected product is a cloud-based solution, the fix has already been deployed across all online versions, so no further action is required on the part of users.

Metrics

References (1)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner INCIBE
Published Mar 26, 2026
Updated Jun 9, 2026
Reserved Mar 16, 2026
CISA Vulnrichment
Updated Mar 26, 2026
NVD
Status Deferred
Modified Jun 17, 2026
Red Hat
Severity n/a
Public date n/a