CVE-2023-37749

Medium severity, CVSS 5.3. EPSS: 0.4% chance of exploitation in the next 30 days.

Incorrect access control in the REST API endpoint of HubSpot v1.29441 allows unauthenticated attackers to view users' data without proper authorization.

Published 2025-10-27. Last modified 2026-06-17.