CVE-2026-57912
Johnson & Johnson Campus Recruiting before 2025-10-31 allows viewing of data provided by recruited students, and notes entered about students by interviewers.
Scoring
- Severity
- HIGH
- CVSS base score
- 7.5
- CVSS vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
- EPSS probability
- 0.42%
- CWE
- CWE-602
- Published
- 2026-06-26
- Last modified
- 2026-06-26
Affected products
- Johnson & Johnson Campus Recruiting
Weakness type
Related vulnerabilities
- CVE-2026-77999 — Joomla Extension - j2commerce.com - Unauthenticated PayPal callback forgery leading to order confirmation fraud in J2Store 1.0.0-3.3.21, 4.0.0-4.0.21, 4.1.0-4.1.6
- CVE-2026-84841 — tsi-coop tsi-dpdp-cms client-side enforcement of server-side security
- CVE-2026-84110 — Releasit Releasit COD Form & Upsells OTP Validation client-side enforcement of server-side security
- CVE-2026-73267 — Clusterclaims-controller: managedcluster deletion keyed solely on clusterclaim.spec.namespace with no local ownership check
- CVE-2026-77026 — Joomla Extension - tassos.gr - Client-controlled validation bypass in Convert Forms extension < 5.2.5
- CVE-2026-45274 — MyBooks: Unauthenticated Registration Bypass via Missing Server-Side ALLOW_REGISTER Enforcement
- CVE-2026-67363 — Joomla Extension - balbooa.com - Pre-auth Payment Amount Tampering in Balbooa Forms < 2.4.3.2
- CVE-2026-73627 — JupyterLab 4.6.0 Plugin Manager Lock-Rule Enforcement Bypass