CVE-2026-57912: Johnson & Johnson Campus Recruiting Data Exposure Vulnerability
Johnson & Johnson's Campus Recruiting platform has a data exposure vulnerability that allows unauthorized access to sensitive information submitted by student job candidates. Specifically, attackers can view personal data that students provided during the application process as well as private interviewer notes and assessments about those candidates. This vulnerability affects versions released before October 31, 2025, and requires no authentication or user interaction to exploit—an attacker on the network can simply request the data directly.
Source data · NVD / CISA · public domain
- CVSS
- 3.1 · 7.5 HIGH · CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
- Weaknesses (CWE)
- CWE-602
- Affected products
- 0 configuration(s)
- Published / Modified
- 2026-06-26 / 2026-06-26
NVD description (verbatim)
Johnson & Johnson Campus Recruiting before 2025-10-31 allows viewing of data provided by recruited students, and notes entered about students by interviewers.
1 reference(s) · View on NVD →
SEC.co analysis · AI-assisted, reviewed against source
Technical summary
CVE-2026-57912 is an authentication bypass and information disclosure flaw in Johnson & Johnson's Campus Recruiting application. The vulnerability stems from inadequate access controls (CWE-602) that fail to enforce proper authorization checks on endpoints exposing candidate records and recruiter commentary. The CVSS 3.1 vector (7.5 HIGH, CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N) indicates network-accessible exposure with no prerequisites, low attack complexity, and high confidentiality impact. The lack of integrity or availability impact suggests the vulnerability is read-only, enabling passive data harvesting rather than data modification or system disruption.
Business impact
Exposure of candidate personal data and recruiter assessments creates multiple business risks: loss of competitive recruiting intelligence, reputational damage from privacy violations, potential regulatory exposure under data protection laws (GDPR, CCPA, state privacy regulations), candidate trust erosion, and legal liability if breached data is misused. Recruiting platforms often contain sensitive information including contact details, educational records, employment history, and confidential evaluation notes that could be leveraged for social engineering, competitive intelligence gathering, or identity theft. The scope of impact depends on the number of active candidates in the system and the retention period of historical recruiting data.
Affected systems
Johnson & Johnson Campus Recruiting platform versions released prior to October 31, 2025 are vulnerable. No specific product version numbers are provided in vendor advisories reviewed; organizations using this platform should verify their deployment date and check J&J's official security notices for exact version scope and whether internal or externally facing instances are affected.
Exploitability
The vulnerability presents moderate-to-high exploitability risk. The CVSS vector indicates no authentication required, no user interaction needed, and network-level accessibility—meaning an attacker without credentials can craft requests to retrieve candidate data from the internet. Attack complexity is low, suggesting the exploitation method is straightforward and does not require specialized techniques or race conditions. However, no evidence of public exploit code or active in-the-wild exploitation has been reported as of the vulnerability's publication date. The fact that it is not listed on CISA's Known Exploited Vulnerabilities (KEV) catalog suggests limited documented exploitation, but organizations should not assume this guarantees continued non-exploitation.
Remediation
Organizations running Johnson & Johnson Campus Recruiting should immediately upgrade to a patched version released on or after October 31, 2025. Verify the exact patched version numbers against J&J's official security advisory. Interim mitigations prior to patching may include network segmentation to restrict access to the recruiting platform, implementation of web application firewalls (WAF) with rules blocking unauthorized data extraction patterns, and review of access logs to detect prior unauthorized data access. Once patched, conduct a post-incident review to identify any exposed records during the vulnerability window.
Patch guidance
Patches are expected to be available in J&J's Campus Recruiting releases dated October 31, 2025 or later. Verify patch availability by consulting J&J's official security advisories and release notes. Organizations should prioritize patching this platform given the high sensitivity of recruiting data and the ease of exploitation. Plan a maintenance window to apply updates without disrupting active recruiting cycles. Test patches in a non-production environment before broad deployment. Document the patch date and version for compliance and audit purposes.
Detection guidance
Monitor for suspicious access patterns to the Campus Recruiting platform: requests to data endpoints by non-recruiter IP addresses, bulk downloads of candidate records, unusual query parameters attempting to bypass authorization, or access from geographic locations inconsistent with recruiting team locations. Review web server and application logs for GET requests to candidate data endpoints without corresponding authentication tokens or with invalid/expired session markers. Set alerts for failed authentication attempts followed by successful data retrieval. Consider logging all access to recruiter notes and candidate records at the database level to establish a complete audit trail. Network-based detection should focus on data exfiltration patterns—large outbound transfers from the recruiting platform to external IPs.
Why prioritize this
This vulnerability merits high priority due to the combination of (1) high CVSS score (7.5), (2) zero authentication requirement, (3) unauthenticated network accessibility, (4) sensitivity of exposed data (personal information and confidential hiring assessments), and (5) low barrier to exploitation. While not yet on the KEV catalog, the ease of attack and likelihood of exploitation by competitors or threat actors seeking candidate data justifies immediate remediation. Recruiting platforms are not typically targets for ransomware, but data theft and competitive intelligence gathering are realistic threat scenarios.
Risk score, explained
The CVSS 3.1 score of 7.5 (HIGH) reflects high confidentiality impact (unauthenticated disclosure of sensitive personal and assessment data), no integrity impact (read-only access), and no availability impact (no denial of service). The network-based attack vector (AV:N), low attack complexity (AC:L), and lack of privilege or user interaction requirements (PR:N, UI:N) maximize the score. The unchanged scope (S:U) indicates the impact is limited to the vulnerable component itself. This score appropriately captures the risk of data exposure to a broad threat landscape, though it does not quantify business-specific factors like the size of the candidate database or regulatory exposure, which organizations should layer into their own risk assessment.
Frequently asked questions
Does this vulnerability allow attackers to modify candidate records or delete them?
No. The CVSS vector indicates confidentiality impact only (C:H/I:N/A:N), meaning the vulnerability enables reading data but not modifying or deleting it. The exposure is limited to unauthorized viewing of information already in the system.
Is my organization affected if we use J&J Campus Recruiting internally but with IP restrictions?
Possibly. The CVSS assessment shows network accessibility (AV:N) with no prerequisites, which suggests the vulnerability is exploitable remotely. However, network-level defenses such as VPN-only access or IP whitelisting can provide defense-in-depth. Verify your platform version against J&J's advisory and patch regardless of network controls.
What kind of data is at risk?
Student applicants typically provide contact information, education history, employment background, and sometimes government-issued identifiers. Interviewer notes may include subjective assessments, interview performance ratings, salary expectations, and personal observations. All of this is sensitive and attractive to competitors, social engineers, and identity thieves.
Is this vulnerability being actively exploited in the wild?
As of the publication date, the vulnerability is not listed on CISA's Known Exploited Vulnerabilities (KEV) catalog, which suggests no verified public exploitation has been reported. However, the absence of KEV status does not guarantee that exploitation is not occurring; it means no definitive evidence has reached CISA. Organizations should treat this as a credible threat and patch promptly.
This analysis is provided for informational and educational purposes. SEC.co does not provide legal, compliance, or business advisory services. Organizations must verify all patch information, version numbers, and release dates directly from Johnson & Johnson's official security advisories and product documentation. This vulnerability analysis does not constitute professional security advice and should be reviewed by qualified security personnel within your organization. Patch testing should be conducted in controlled, non-production environments before deployment. Consult your legal and compliance teams regarding regulatory obligations for data breach notification or forensic investigation if unauthorized access is confirmed. SEC.co makes no warranty regarding the completeness or accuracy of this analysis and disclaims liability for actions taken in reliance on this information. Source: NVD (public-domain), retrieved 2026-08-05. Analysis generated by SEC.co (claude-haiku-4-5).
Weaknesses (CWE)
Related vulnerabilities
- CVE-2026-11011HIGHChrome Password Manager Site Isolation Bypass – Patch Guidance
- CVE-2026-11092HIGHChrome DevTools Policy Enforcement Flaw Enables Privilege Escalation via Malicious Extension
- CVE-2026-11236HIGHGoogle Chrome Sandbox Escape via Web Bluetooth Policy Enforcement Flaw
- CVE-2026-13903HIGHChrome Bluetooth Privilege Escalation – CVSS 8.8 HIGH – Patch to 150.0.7871.47
- CVE-2026-14036HIGHChrome Bluetooth Privilege Escalation Vulnerability – Patch Guidance
- CVE-2026-14041HIGHChrome Serial API Privilege Escalation Vulnerability
- CVE-2026-14086HIGHGoogle Chrome HID Remote Code Execution Vulnerability
- CVE-2026-54104HIGHU.S. Government GAO EPDS and CBCA EDS Privilege Escalation (CVSS 8.8)