logo

Side of Fries With That Bug? Hacker Finds Flaws in McDonald's Staff, Partner Hubs

ID: f978b6c2-c888-525d-920a-b4c0e8396e1d

STIX ID: report--f978b6c2-c888-525d-920a-b4c0e8396e1d

Feed Name: Dark Reading

Threat Score
65/100

Date Published: 2025-08-20

Date Updated: 2026-04-21

Author: Elizabeth Montalbano, Contributing Writer

...
...

An ethical hacker reported discovering multiple security flaws across McDonald's partner and employee systems — including client-side-only authentication, plaintext password disclosure, exposed API keys in JavaScript, listable Algolia search indexes containing personal data, OAuth/authentication misconfigurations, and an unauthenticated admin API that allowed arbitrary content changes. The issues reportedly enabled listing users, sending official-looking notifications (facilitating phishing), accessing internal documents and employee contact information, and modifying franchise content; the researcher says the problems were reported and fixed, and recommends public security contacts, security.txt, and a bug-bounty program.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.