Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Security Flaw in Tata’s B2B Platform Exposed User Accounts

Security Flaw in Tata’s B2B Platform Exposed User Accounts

Posted on August 26, 2026 By CWS

A significant security vulnerability in Tata Nexarc, a B2B procurement platform designed for small and medium enterprises in India, was found to permit account takeovers using merely a registered phone number.

The flaw involved an exposed one-time password (OTP) in a decryptable API response, negating the need for SMS interception or phishing. Tata Nexarc facilitates business transactions with steel and building material suppliers.

Tata Nexarc’s OTP Vulnerability Exposed

A security expert revealed that the platform’s OTP login mechanism used an endpoint, CheckForUsersRegisteredWithEmailOrMobileNoAndSendOTP.do, which dispatched an OTP to the mobile number provided. Crucially, this same process also returned the OTP within the API response, accessible to the client.

Despite the encryption of API traffic, the encryption and decryption logic operated in client-side JavaScript through AES. This setup allowed the researcher to insert a breakpoint in the JavaScript, revealing the plaintext OTP.

Implications of the Security Breach

The decrypted API response included the otpGeneratedForMobile field, presenting the exact OTP that was sent to the account holder via SMS. Consequently, an attacker could input a victim’s mobile number, obtain the OTP from the API response, and complete the login as that user. This flaw turned the OTP system into a vulnerability for client-side secret disclosure.

OTPs are supposed to verify control over a phone number or email account. However, returning the OTP in a browser-accessible manner nullifies this protection. The expert noted that the visible login functionality did not require the exposed OTP field, rendering its presence an unnecessary risk.

Response and Resolution

According to Eaton-Works, the potential damage hinges on the affected account’s privileges. Tests showed that a guessed mobile number linked to Tata Business Hub’s main account granted administrator access, enabling comprehensive control over corporate pages, employee management, and more.

Reportedly, the researcher also managed to access an administrative account connected to Tata Steel using the organization’s associated mobile number. Although the disclosure mentioned no method for mass phone number extraction, attackers could target individuals through public information or compromised accounts.

The vulnerability was reported to India’s Computer Emergency Response Team (CERT-In) on July 30, 2026, and was confirmed fixed by July 31, 2026. The researcher disclosed on August 24 that the vulnerable otpGeneratedForMobile field had been removed from the API response.

This incident underscores a crucial rule in OTP implementation: authentication codes must never be visible to clients, stored in plaintext, or exposed via browser-accessible APIs. Instead, servers should internally validate OTPs, limit data in responses, enforce expiration, and monitor authentication attempts to prevent account takeovers.

Cyber Security News Tags:account takeover, API security, B2B platform, CERT-In, Cybersecurity, data breach, India, OTP vulnerability, security flaw, Tata

Post navigation

Previous Post: AliExpress Employs WebAudio for Device Fingerprinting

Related Posts

Critical Zero-Day Flaws in PDF Software Risk Data Exposure Critical Zero-Day Flaws in PDF Software Risk Data Exposure Cyber Security News
Optimize SOC Efficiency with Threat Intelligence Feeds Optimize SOC Efficiency with Threat Intelligence Feeds Cyber Security News
ZeroDayRAT: New Spyware Targeting Android and iOS ZeroDayRAT: New Spyware Targeting Android and iOS Cyber Security News
nsKnox Launches Adaptive Payment Security™, Solving the “Impossible Triangle” of B2B Fraud Prevention nsKnox Launches Adaptive Payment Security™, Solving the “Impossible Triangle” of B2B Fraud Prevention Cyber Security News
AWS Middle East Outage Disrupts EC2 and Networking Services AWS Middle East Outage Disrupts EC2 and Networking Services Cyber Security News
Top VPNs for Chrome in 2026: Secure Your Browsing Top VPNs for Chrome in 2026: Secure Your Browsing Cyber Security News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Security Flaw in Tata’s B2B Platform Exposed User Accounts
  • AliExpress Employs WebAudio for Device Fingerprinting
  • WhatsApp Enhances Security: 1 Billion Use Passkeys
  • AI-Driven Botnet ToxNetV2 Targets Linux Systems
  • AI Redefines Vulnerability Management in Cybersecurity

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Security Flaw in Tata’s B2B Platform Exposed User Accounts
  • AliExpress Employs WebAudio for Device Fingerprinting
  • WhatsApp Enhances Security: 1 Billion Use Passkeys
  • AI-Driven Botnet ToxNetV2 Targets Linux Systems
  • AI Redefines Vulnerability Management in Cybersecurity

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark