ON24 Authorization Bypass Vulnerability in Q&A Chat Allowing Data Enumeration

Vulnerability

A vulnerability has been identified in the ON24 engagement platform's Q&A chat feature, specifically within the 'console-survey/api/v1/answer/{EVENTID}/{TIMESTAMP}/' endpoint. This vulnerability allows for authorization bypass through user-controlled keys, enabling unauthenticated attackers to enumerate event IDs and access the complete Q&A history. The exposed data may contain sensitive information such as IDs, private URLs, messages, internal references, and other details meant for authenticated users only. Furthermore, the leaked content could be used to conduct reconnaissance for lateral movement, exploit related systems, or gain unauthorized access to internal applications mentioned in chat messages.

Impact

Exploitation of this vulnerability could lead to unauthorized access to sensitive Q&A chat data, including private messages and internal references, which could be used to facilitate further malicious activities such as lateral movement or exploitation of related systems.

Added: Mar 30, 2026, 2:19 PM
Updated: Mar 30, 2026, 2:19 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
2.5
exploitability
7.4
remediation
0.0
relevance
4.9
threat
0.0
urgency
2.9
incentive
4.2

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.