Sceawere
Vulnerability Detail
CVE-2026-32468UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
Unauthenticated Sensitive Data Exposure in Duitku
Vulnerability Metadata
- Severity
- High
- Score / CVSS
- 7.5
- Creation Date
- 3h ago
- Vendor
- rayhanduitku
- Product
- Duitku Payment Gateway
- Attack Type
- CWE-497 Exposure of Sensitive System Information to an Unauthorized Control Sphere
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
- Attack Complexity
- LOW
Narrative and Response
Description
Unauthenticated Sensitive Data Exposure in Duitku Payment Gateway <= 2.11.14 versions.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "7.5",
"pubDate": "2026-08-18T14:17:05.857Z",
"pubdate": "2026-08-18T14:17:05.857Z",
"executiveSummary": "An unauthenticated sensitive data exposure vulnerability has been identified in the Duitku Payment Gateway plugin <= 2.11.14 versions. This security flaw allows unauthenticated remote attackers to harvest sensitive transactional, configuration, or user data directly from affected systems without requiring valid credentials or prior interaction. The vulnerability poses significant risk implications, potentially exposing proprietary financial data, internal system parameters, or Personally Identifiable Information (PII) to malicious actors.\nThe exploitation requirements are minimal, as the attack vector requires no authentication, privilege elevation, or user interaction over the network. Threat actors possessing network access to the vulnerable endpoint can exploit this flaw to compromise data confidentiality. The impact of successful exploitation includes unauthorized information disclosure, which may facilitate further targeted attacks against the application infrastructure or its user base.",
"technicalDetails": "The root cause of the vulnerability stems from improper access control enforcement within the Duitku Payment Gateway <= 2.11.14 versions, where sensitive endpoints or data retrieval functions fail to validate user authentication and authorization states adequately. Consequently, HTTP requests directed at specific vulnerable components bypass security boundaries, returning sensitive application data directly in the response payload.\nThe attack flow begins when an unauthenticated remote attacker identifies the exposed endpoint or function within the Duitku Payment Gateway plugin. The attacker crafts a standard HTTP request targeting the vulnerable component over the network. Because the underlying logic lacks proper session verification and privilege validation checks, the application processes the request and retrieves the requested information from the backend data store.\nThe vulnerable component responds by transmitting the sensitive data back to the client in cleartext or inadequately protected formats. Network exposure is broad, as the affected functionalities are accessible over standard web protocols (HTTP/HTTPS) to any external entity capable of communicating with the web server hosting the application. Privilege requirements are nonexistent (unauthenticated), and no specific payload execution or post-exploitation persistence mechanism is necessary to achieve the primary data disclosure objective.\nThe post-exploitation impact is characterized by unauthorized access to confidential information, which attackers can leverage for reconnaissance, identity theft, or subsequent compromise of integrated payment infrastructures and customer accounts."
}