Restaurant Brands International Assistant Platform Cleartext Password Transmission Vulnerability

Vulnerability

A vulnerability exists in the Restaurant Brands International (RBI) assistant platform, affecting through September 6, 2025, that allows for the transmission of user account passwords in cleartext via email. This issue arises from an improperly configured user signup process that left accounts open for unauthorized creation, bypassing email verification and exposing sensitive information.

Impact

Exploitation of this vulnerability leads to the unauthorized transmission of user passwords in cleartext, creating a risk of account compromise.

Reproduction

The vulnerability can be reproduced by accessing the open signup endpoint on the RBI assistant platform domains for Burger King, Popeyes, and Tim Hortons. This endpoint allows for the creation of user accounts without email verification, enabling the interception of passwords sent in cleartext emails.

Remediation

RBI has reportedly fixed the vulnerability by addressing the email verification bypass and closing the open user sign-up access.

Added: Oct 17, 2025, 9:23 PM
Updated: Oct 18, 2025, 1:24 AM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
5.0
exploitability
7.6
remediation
0.0
relevance
0.7
threat
6.4
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.