CVE-2026-45248

Hedera Guardian through 3.5.1 contains an authentication bypass vulnerability in the GET /api/v1/demo/registered-users endpoint that allows unauthenticated attackers to retrieve sensitive user information. Attackers can access the endpoint without providing authentication credentials to obtain usernames, Hedera DIDs, parent registry DIDs, system roles, and policy role assignments for all registered users in the system.
Configurations

Configuration 1 (hide)

cpe:2.3:a:hedera:guardian:*:*:*:*:*:*:*:*

History

27 May 2026, 20:33

Type Values Removed Values Added
References () https://github.com/hashgraph/guardian/pull/6076 - () https://github.com/hashgraph/guardian/pull/6076 - Issue Tracking, Patch
References () https://www.vulncheck.com/advisories/hedera-guardian-authentication-bypass-information-disclosure - () https://www.vulncheck.com/advisories/hedera-guardian-authentication-bypass-information-disclosure - Third Party Advisory
CPE cpe:2.3:a:hedera:guardian:*:*:*:*:*:*:*:*
First Time Hedera
Hedera guardian

14 May 2026, 22:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-05-14 22:16

Updated : 2026-05-27 20:33


NVD link : CVE-2026-45248

Mitre link : CVE-2026-45248

CVE.ORG link : CVE-2026-45248


JSON object : View

Products Affected

hedera

  • guardian
CWE
CWE-306

Missing Authentication for Critical Function