CVE-2026-57912 Details
Description
Johnson & Johnson Campus Recruiting before 2025-10-31 allows viewing of data provided by recruited students, and notes entered about students by interviewers.
A vulnerability in the Johnson & Johnson Campus Recruiting web application, affecting versions prior to October 31, 2025, allows unauthorized access to sensitive data submitted by students and notes from interviewers. The issue arises from improper authentication, where a hardcoded API key was used instead of a Microsoft authentication token, enabling access to private recruiter routes and student information.
The Campus Recruiting web application has been updated to replace the API key authentication with Bearer token authentication using MSAL. No specific remediation details for the Audit Tracking Management System vulnerability were provided, but it has also been fixed.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Jun 26, 2026CISA-ADP
Assessed Jun 26, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://eaton-works.com/2026/06/24/jnj-webapp-hacks/ | [email protected] | ExploitRemedyTechnical Analysis |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-602 | Client-Side Enforcement of Server-Side Security | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| Johnson & Johnson Campus Recruiting | < 2025-10-31 |
CPE
Remediation
| |
Change History
2 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 26, 2026 | CVE Modified | CISA-ADP |
| Jun 26, 2026 | New CVE Received | [email protected] |
Volerion