
Hoppscotch patches unauthenticated onboarding config takeover (CVE-2026-28215)
CVE-2026-28215 lets unauthenticated attackers overwrite self-hosted Hoppscotch infrastructure config via POST /v1/onboarding/config, exposing OAuth credentials and plaintext secrets; fixed in 2026.2.0.
NewsApplication SecuritySupply Chain
26 Feb 2026
