logo

Tata B2B Platform Flaw Lets Attackers Bypass OTP and Take Over Accounts

ID: d9f32d20-87b0-5403-94fa-8b249206d18c

STIX ID: report--d9f32d20-87b0-5403-94fa-8b249206d18c

Feed Name: Cyber Press

Threat Score
60/100

Date Published: 2026-08-25

Date Updated: 2026-08-25

Author: Tamilselvan

...
...

Tata Nexarc's B2B platform returned an AES-encrypted API field that client-side JavaScript could decrypt to reveal plaintext login OTPs, allowing an attacker who knows a registered mobile number to potentially complete passwordless authentication and seize accounts with administrative capabilities; the flaw was reported to CERT-In and fixed by removing the otpGeneratedForMobile field.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.