A critical authentication flaw in Tata Nexarc, Tata’s B2B procurement platform for small and medium businesses in India, exposed one-time passwords in a browser-accessible API response and allowed account takeover with only a victim’s registered mobile number. The vulnerable OTP login flow returned the generated code in a decryptable response field, enabling an attacker to retrieve the OTP client-side and authenticate without intercepting SMS messages or brute-forcing the code.
The researcher said the issue could expose high-privilege accounts, including administrator access associated with Tata Business Hub and an account linked to Tata Steel. The flaw was reported to CERT-In, acknowledged the same day, and remediated by removing the otpGeneratedForMobile field from the API response; public discussion later highlighted the case as a reminder that OTP values must never be returned to clients or exposed through browser-accessible APIs.

See affected versions and whether adversaries are exploiting it.
4 events from the most recent confirmed update back to the earliest known activity.
The researcher published a disclosure describing how Tata Nexarc's OTP login flow exposed one-time passwords in API responses, enabling account takeover with only a victim's phone number. The disclosure also described impact to high-privilege accounts, including administrator access tied to Tata Business Hub and an account linked to Tata Steel.
CERT-In confirmed the flaw was fixed by removing the otpGeneratedForMobile field from the API response. This remediation stopped the application from returning the SMS OTP to the client.
CERT-In acknowledged receipt of the Tata Nexarc vulnerability report on the same day it was submitted. This established official awareness of the account-takeover issue.
A researcher reported a critical authentication flaw in Tata Nexarc to CERT-In. The issue allowed account takeover because the platform returned the generated OTP in a decryptable API response.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.