Exploiting vulnerabilities in Johnson and Johnson web apps

A security researcher details how they exploited vulnerabilities in Johnson & Johnson web applications, including a campus recruiting site and an internal audit system. The researcher demonstrated how improper authentication allowed unauthorized access to sensitive student and corporate data.
Why it matters
The report serves as a case study on the risks of hardcoded API keys and insecure client-side authentication in enterprise software.
Eaton • Jun 24, 2026 Copy Link Share Today I am revealing vulnerabilities I found in 2 very different Johnson & Johnson web apps. One is a vulnerability in a college campus recruiting system that exposed details of nearly 1,000 students, and the other is an admin takeover of an internal audit system used by 20 companies. Let s dive in!
The article is a technical disclosure of security vulnerabilities without political bias.
Get smarter about the news
Sign up free for a feed built around what you actually care about, Dive Deeper research on any story, and the full text of every article.
Create free accountAlready have an account? Sign in