Unauthorized Access in GoJobs Job Board API
CVE-2026-44341

5.3MEDIUM

Key Information:

Vendor

Karnop

Status
Vendor
CVE Published:
12 May 2026

What is CVE-2026-44341?

The GoJobs Job Board platform's REST API has a security vulnerability that enables unauthenticated users to access sensitive job details. This occurs due to flaws in the API's job retrieval endpoint, which fails to enforce necessary authentication and authorization protocols. As a result, attackers can manipulate object identifiers, potentially leading to unauthorized disclosure of job data. Organizations using GoJobs should implement proper access controls to mitigate this risk.

Affected Version(s)

gojobs <= 2cc74a78dcf101c089ea209f2aaefef0674f6b55

References

CVSS V3.1

Score:
5.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.