Overview
The target platform's data API performed no authentication or authorization at all. The public citizen portal exposes only curated open data, but the underlying data API returned, without authentication, the full dataset catalog (including employee numbers) and the raw row data of each dataset. That included internal operational data not listed in the public portal catalog: a real-name roster of residents' association officers and contacts of staff responsible for serious-accident facilities. All of it was exposed in bulk without authentication.
This is an abridged record. The product name, vendor name, paths, parameter names and reproduction steps are masked.
Disclosure details
- ID: FVE-2026-8617-75112
- Group: Web
- Status: Published
- Severity: High (CVSS 7.5,
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N) - Submitted: 2026-07-19, issued: 2026-08-10
- Visibility: Redacted
Attack flow
[Step 1] Collect the dataset catalog without authentication
- Call the catalog API with no credentials
- Obtain a list of about 500 datasets plus internal metadata such as employee numbers
[Step 2] Identify datasets with personal-data columns
- Inspect each dataset's column schema
- Select datasets that declare name and contact columns
[Step 3] Read raw row data without authorization
- Call the row data API without authentication
- Returns real names, council, position and administrative district of 4,510 residents' association officers
- A separate dataset returns facility staff names and contacts
Impact
- Exposure of real names, affiliation, position and administrative district of 4,510 residents' association officers and committee members
- Exposure of names and contacts (extensions) of facility staff and managers
- Employee numbers in the catalog response can be abused to enumerate internal accounts
- Collected names, affiliations and contacts can be abused for impersonation and targeted phishing
- Allows mass collection when combined with sequential integer identifiers
Remediation
- Apply an authentication gate to every data API path.
- Enforce the authorization model on the server, such as each dataset's department permission code.
- Separate public datasets from internal operational datasets, and do not expose internal datasets through an unauthenticated API.
- Minimize internal identifiers such as employee numbers in catalog responses.
Platform evaluation
- Low
AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N/SH:D/DO:A
CWE
- CWE-306: Missing Authentication for Critical Function
- CWE-200: Exposure of Sensitive Information to an Unauthorized Actor
- CWE-284: Improper Access Control