CVE-2023-37749 Details
Description
Incorrect access control in the REST API endpoint of HubSpot v1.29441 allows unauthenticated attackers to view users' data without proper authorization.
A vulnerability exists in HubSpot's REST API endpoint, specifically in the Users UI, that allows unauthenticated attackers to access users' data without proper authorization. This issue arises from incorrect access control, enabling the retrieval of sensitive information such as names and emails by manipulating intercepted UI requests. The vulnerability affects HubSpot version 1.29441.
HubSpot has acknowledged this vulnerability and applied a server-side fix. No customer action was required.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Oct 27, 2025CISA-ADP
Assessed Oct 27, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-284 | Improper Access Control | CISA-ADP |
Affected Products
| Product | Versions |
|---|---|
| HubSpot | All versions |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Oct 27, 2025 | CVE Modified | CISA-ADP |
| Oct 27, 2025 | New CVE Received | [email protected] |
Volerion