CVE-2025-65784: 
NixOS vulnerability analysis and mitigation

Overview

CVE-2025-65784 is a Broken Object Level Authorization (BOLA/IDOR) vulnerability in Hubert Imoveis e Administracao Ltda's Hub application (v2.0, version 1.27.3) for iOS, Android, and Web platforms. It allows authenticated attackers with low-level privileges to access other users' personally identifiable information (PII) via crafted API requests. The vulnerability was discovered by Carlos Artmann in November 2025 and published on January 13, 2026. It carries a CVSS v3.1 base score of 6.5 (Medium), assessed by CISA-ADP (Feedly, GitHub PoC).

Technical details

The root cause is a missing object-level authorization check in the application's API endpoints (CWE-639 / CWE-918), classified by CISA-ADP as CWE-918 (SSRF), though the researcher's write-up more precisely identifies it as BOLA/IDOR (CWE-639). An authenticated low-privilege user can manipulate object identifiers (e.g., numeric unit IDs) in API requests to retrieve records belonging to arbitrary other users. Specifically, the vulnerable endpoints include /api/v1/unidades/{id}/GRENO/pessoas and related enderecamento queries hosted at api-cadastro.hubert.com.br, where simply changing the numeric ID in the URL path returns another user's data without any authorization validation (GitHub PoC).

Impact

Successful exploitation results in unauthorized disclosure of sensitive PII belonging to other platform users, including national ID numbers (CPF), full names, email addresses, and potentially other personal details. The attack requires only a valid low-privilege account and network access, with no user interaction needed. There is no integrity or availability impact, but the confidentiality breach could facilitate identity theft, social engineering, or regulatory violations (e.g., LGPD in Brazil) (Feedly, GitHub PoC).

Exploitability

A public proof-of-concept (PoC) is available on GitHub, published by the discoverer Carlos Artmann, demonstrating the exploit via simple API URL manipulation. There is no evidence of active in-the-wild exploitation at this time, and the vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. The EPSS score is approximately 0.014% (0.000140), indicating a very low probability of exploitation in the near term (Feedly, GitHub PoC).

Exploitation steps

  1. Authentication: Obtain a valid low-privilege account on the Hub 2.0 platform (v1.27.3) — this could be any registered tenant or user account.
  2. Reconnaissance: Identify the API base URL (api-cadastro.hubert.com.br) and enumerate accessible endpoints, particularly /api/v1/unidades/{id}/GRENO/pessoas.
  3. Object ID manipulation: Send an authenticated HTTP GET request to the endpoint, substituting the numeric unit ID (e.g., 1839) with other integer values to retrieve records for different users.
  4. PII extraction: Parse the API response to extract victim PII such as CPF (national ID), name, and other personal details.
  5. Email enumeration: Use the retrieved identifiers to query the enderecamento endpoint (/api/v1/unidades/{id}/GRENO%2041/enderecamento?codigoCondominio=&unidade=GRENO%20&codigoPesUni=) to obtain email addresses and additional contact information for targeted users (GitHub PoC).

Indicators of compromise

  • Network: Repeated authenticated API requests to /api/v1/unidades/*/GRENO/pessoas or /api/v1/unidades/*/GRENO*/enderecamento with sequentially or randomly varying numeric IDs from a single source IP.
  • Logs: API access logs showing a single authenticated user account querying unit IDs that do not correspond to their own assigned unit(s) in rapid succession.
  • Behavioral: Unusual volume of cross-user data retrieval from a low-privilege account; access patterns inconsistent with normal user behavior (e.g., iterating through hundreds of unit IDs in a short timeframe) (GitHub PoC).

Mitigation and workarounds

No vendor patch has been released as of the time of this report. Recommended mitigations include implementing strict server-side object-level authorization checks on all API endpoints to ensure users can only access resources associated with their own account. Organizations should enforce role-based access control (RBAC) and validate that the requested object ID belongs to the authenticated user before returning data. Additionally, monitoring API access logs for anomalous cross-user data access patterns and restricting network access to the API where feasible are advised interim measures (Feedly).

Additional resources


Source: This report was generated using AI

Related NixOS vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-103678HIGH8.1
  • NixOS logoNixOS
  • tnef
NoNoOct 01, 2026
CVE-2026-103680MEDIUM6.5
  • NixOS logoNixOS
  • tnef
NoNoOct 01, 2026
CVE-2026-103679MEDIUM6.5
  • NixOS logoNixOS
  • tnef
NoNoOct 01, 2026
CVE-2026-103497MEDIUM5.5
  • YouTrack logoYouTrack
  • cpe:2.3:a:jetbrains:youtrack
NoYesOct 01, 2026
CVE-2026-103496MEDIUM5.4
  • YouTrack logoYouTrack
  • youtrack
NoYesOct 01, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management