HIGH 7.5

CVE-2026-57913: Johnson & Johnson ATMS Authentication Bypass Exposing Audit Documents

Johnson & Johnson's Audit Tracking Management System (ATMS) contains a flaw that allows unauthorized users to access sensitive meeting minutes and transcripts without authentication. An attacker on the network can view confidential audit-related documents and discussions that should be restricted to authorized personnel. The vulnerability affects versions released before April 21, 2026, and requires immediate patching to prevent further exposure of privileged information.

Source data · NVD / CISA · public domain

CVSS
3.1 · 7.5 HIGH · CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Weaknesses (CWE)
CWE-602
Affected products
0 configuration(s)
Published / Modified
2026-06-26 / 2026-06-26

NVD description (verbatim)

Johnson & Johnson Audit Tracking Management System (ATMS) before 2026-04-21 allows viewing of meeting minutes and transcripts.

1 reference(s) · View on NVD →

SEC.co analysis · AI-assisted, reviewed against source

Technical summary

CVE-2026-57913 is an authentication bypass vulnerability in ATMS that stems from improper access controls (CWE-602). The flaw permits unauthenticated, network-based access to meeting minutes and transcripts with no user interaction required. The CVSS 3.1 score of 7.5 (HIGH) reflects the high confidentiality impact—attackers can read sensitive audit documentation—balanced against no integrity or availability impact. The attack vector is network-based with low complexity and no privilege requirements, making exploitation straightforward for any attacker with network access to the system.

Business impact

Exposure of audit meeting minutes and transcripts creates significant compliance and governance risks. Organizations using ATMS may face regulatory scrutiny if audit discussions, findings, or internal control assessments are disclosed to unauthorized parties. This can undermine audit independence, compromise sensitive deliberations between auditors and management, and potentially violate data protection obligations. The confidentiality breach may also damage trust in the audit process and trigger mandatory breach notifications depending on jurisdiction and data classification.

Affected systems

Johnson & Johnson's Audit Tracking Management System versions released before April 21, 2026 are affected. Organizations running ATMS should verify their current version and check the vendor advisory for the complete list of impacted product editions and deployment configurations.

Exploitability

This vulnerability has a low barrier to exploitation. No authentication is required, the attack complexity is low, and it can be executed remotely over the network without user interaction. Any attacker with network-level access to the ATMS can immediately retrieve meeting minutes and transcripts. The simplicity of the attack surface and lack of prerequisites mean this flaw poses an elevated risk even in the absence of active public exploits.

Remediation

Apply the security patch released by Johnson & Johnson for ATMS versions dated April 21, 2026 or later. The patch restores proper access controls to prevent unauthenticated access to meeting minutes and transcripts. Organizations should prioritize patching, as the vulnerability affects core audit documentation and requires no special conditions to exploit. Verify patch deployment across all ATMS instances in your environment before considering remediation complete.

Patch guidance

Obtain and deploy the April 21, 2026 or later release of Johnson & Johnson ATMS. Consult the vendor's security advisory for step-by-step patch instructions, rollback procedures, and any compatibility notes with dependent systems. Test the patch in a non-production environment to ensure audit workflows and reporting functions remain unaffected. Schedule patching during a maintenance window to minimize disruption to ongoing audit activities. Confirm that access controls are properly enforced post-patch by validating that unauthenticated users cannot retrieve meeting minutes.

Detection guidance

Monitor ATMS logs for unusual requests to meeting minutes and transcript endpoints, particularly from users or service accounts without audit roles. Look for repeated failed authentication attempts followed by successful data retrieval, or patterns of bulk document access. Network intrusion detection signatures should flag unauthenticated access to sensitive audit endpoints. Enable audit logging at the application layer to capture who accessed which audit documents and when. Compare access patterns before and after patching to establish baseline behavior and identify any lingering unauthorized access.

Why prioritize this

This vulnerability warrants high priority remediation due to the direct exposure of sensitive audit documentation, the trivial ease of exploitation, and the governance implications. Audit-related materials often contain confidential strategic information, control weaknesses, and executive deliberations. The combination of unauthenticated network access and high confidentiality impact makes this a critical control gap that should be closed before addressing lower-impact flaws.

Risk score, explained

The CVSS 3.1 score of 7.5 (HIGH) reflects a vulnerability with severe confidentiality consequences but no impact on system integrity or availability. The network attack vector, low complexity, and lack of authentication or user interaction requirements place this in the upper tier of exploitability. The score appropriately captures the practical risk: any attacker can remotely read sensitive audit data with minimal effort, but cannot modify or destroy it. Organizations should treat this as a confidentiality-tier incident requiring expedited patching.

Frequently asked questions

Can this vulnerability be exploited from outside the corporate network?

Yes. The attack vector is network-based (AV:N), meaning an attacker with any network-level access to the ATMS—whether from the internet, a partner connection, or a compromised internal system—can exploit it. If ATMS is Internet-facing or accessible via VPN, external attackers are a concern. If it is internal-only, the threat model is limited to insider actors and compromised credentials.

Does the vulnerability allow attackers to modify or delete audit records?

No. The CVSS vector indicates no integrity impact (I:N) and no availability impact (A:N). This flaw permits reading only; attackers cannot alter meeting minutes, add false findings, or remove audit evidence. The risk is disclosure of confidential information, not tampering.

What should we do if we cannot patch immediately?

Implement compensating controls: restrict network access to ATMS to trusted IP ranges and authenticated users only, disable external access if not business-critical, and increase monitoring and logging of access attempts. Apply the vendor patch as soon as possible—compensating controls are temporary measures and do not eliminate the underlying flaw.

Is this vulnerability being actively exploited?

As of the published date, this vulnerability is not listed on the CISA Known Exploited Vulnerabilities (KEV) catalog, indicating no confirmed public exploitation in the wild. However, the low barrier to exploitation means attackers could begin weaponizing it; prompt patching is essential to stay ahead of any emerging attack activity.

This analysis is provided for informational purposes and represents the security community's current understanding of CVE-2026-57913 as of the publication date. No exploit code or weaponized proof-of-concept is included. Patch version numbers and vendor advisory references should be verified directly against official Johnson & Johnson security bulletins. Organizations are responsible for assessing risk within their own environment, testing patches before deployment, and consulting with vendors on compatibility and support. SEC.co makes no warranty regarding the completeness, accuracy, or fitness of this analysis for any particular purpose. Source: NVD (public-domain), retrieved 2026-08-05. Analysis generated by SEC.co (claude-haiku-4-5).