OWASP's API Security Top 10 identifies broken object-level and function-level authorization, excessive data exposure, security misconfiguration, and unsafe trust boundaries as leading API risks, warning that business logic abuse and operational gaps often turn ordinary endpoints into high-impact exposures. Those patterns were reflected in newly disclosed incidents involving both enterprise software and consumer-facing platforms, where low-privileged access was enough to reach data and functions intended for administrators or other users.
In CVE-2026-46515, Frogman versions before 1.6.3 allowed users with only PERM_READ privileges to access administrative PBX data through MCP and HTTP APIs, including AMI manager secrets, outbound dial PINs, SIP secrets, backup paths, CDR history, and even root SSH connection commands; the flaw also enabled arbitrary execution of saved GraphQL queries and was rated CVSS 9.3. Separately, a bug bounty report on Target's Academy platform showed how two seemingly low-risk APIs could be chained to enumerate users and expose PII at scale, underscoring how weak authorization controls across interconnected endpoints can escalate routine API functionality into serious data disclosure.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
5 events from the most recent confirmed update back to the earliest known activity.
The researcher said the Target Academy API finding resulted in a $2,000 bug bounty payout.
A bug bounty write-up described how two Target Academy API endpoints could be chained by a low-privileged user to enumerate users and expose sensitive PII at scale, resulting in a Broken Access Control finding.
The CVE advisory states that Frogman version 1.6.3 fixes the authorization flaw that exposed admin-grade data and enabled arbitrary saved GraphQL execution to low-privileged users.
A critical missing-authorization vulnerability affecting Frogman versions before 1.6.3 was disclosed, showing that PERM_READ users could access sensitive administrative data and execute saved GraphQL queries. The issue was rated CVSS 9.3 and described as remotely exploitable.
OWASP released its 2023 API Security Top 10, outlining major API risk categories including authorization failures, authentication weaknesses, SSRF, misconfiguration, inventory gaps, and insecure trust in third-party APIs.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
4 references tracked. Mallory keeps watching after this page renders.
meetcyber.net
Open sourceinfosecwriteups.com
Open sourcecvefeed.io
Open sourceowasp.org
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.