
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-65784 is a Broken Object Level Authorization (BOLA/IDOR) vulnerability in Hubert Imoveis e Administracao Ltda's Hub application (v2.0, version 1.27.3) for iOS, Android, and Web platforms. It allows authenticated attackers with low-level privileges to access other users' personally identifiable information (PII) via crafted API requests. The vulnerability was discovered by Carlos Artmann in November 2025 and published on January 13, 2026. It carries a CVSS v3.1 base score of 6.5 (Medium), assessed by CISA-ADP (Feedly, GitHub PoC).
The root cause is a missing object-level authorization check in the application's API endpoints (CWE-639 / CWE-918), classified by CISA-ADP as CWE-918 (SSRF), though the researcher's write-up more precisely identifies it as BOLA/IDOR (CWE-639). An authenticated low-privilege user can manipulate object identifiers (e.g., numeric unit IDs) in API requests to retrieve records belonging to arbitrary other users. Specifically, the vulnerable endpoints include /api/v1/unidades/{id}/GRENO/pessoas and related enderecamento queries hosted at api-cadastro.hubert.com.br, where simply changing the numeric ID in the URL path returns another user's data without any authorization validation (GitHub PoC).
Successful exploitation results in unauthorized disclosure of sensitive PII belonging to other platform users, including national ID numbers (CPF), full names, email addresses, and potentially other personal details. The attack requires only a valid low-privilege account and network access, with no user interaction needed. There is no integrity or availability impact, but the confidentiality breach could facilitate identity theft, social engineering, or regulatory violations (e.g., LGPD in Brazil) (Feedly, GitHub PoC).
A public proof-of-concept (PoC) is available on GitHub, published by the discoverer Carlos Artmann, demonstrating the exploit via simple API URL manipulation. There is no evidence of active in-the-wild exploitation at this time, and the vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. The EPSS score is approximately 0.014% (0.000140), indicating a very low probability of exploitation in the near term (Feedly, GitHub PoC).
api-cadastro.hubert.com.br) and enumerate accessible endpoints, particularly /api/v1/unidades/{id}/GRENO/pessoas.1839) with other integer values to retrieve records for different users.enderecamento endpoint (/api/v1/unidades/{id}/GRENO%2041/enderecamento?codigoCondominio=&unidade=GRENO%20&codigoPesUni=) to obtain email addresses and additional contact information for targeted users (GitHub PoC)./api/v1/unidades/*/GRENO/pessoas or /api/v1/unidades/*/GRENO*/enderecamento with sequentially or randomly varying numeric IDs from a single source IP.No vendor patch has been released as of the time of this report. Recommended mitigations include implementing strict server-side object-level authorization checks on all API endpoints to ensure users can only access resources associated with their own account. Organizations should enforce role-based access control (RBAC) and validate that the requested object ID belongs to the authenticated user before returning data. Additionally, monitoring API access logs for anomalous cross-user data access patterns and restricting network access to the API where feasible are advised interim measures (Feedly).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."