Whistleblower Woes: Convercent’s Security Blunders Exposed!
Convercent’s whistleblowing platform had more leaks than a colander. Security misconfigurations and customer enumeration exposed vulnerabilities, now with shiny new CVE identifiers to boot. Keep your secrets safe, folks!

Hot Take:
In the latest episode of ‘Oops, We Did It Again,’ Convercent’s whistleblowing platform reveals that security misconfigurations can be as slippery as a greased ferret. With vulnerabilities worthy of their own CVE trophies, it just goes to show that even the platforms meant to protect secrets aren’t immune to spilling some of their own.
Key Points:
- Convercent’s whistleblowing platform has been caught with multiple security misconfigurations.
- These vulnerabilities have now been assigned CVE identifiers: CVE-2025-34411 and CVE-2025-34412.
- Customer enumeration exposure is one of the key issues highlighted.
- The issue was first reported on December 5 and updated with CVE information on December 15.
- The Full Disclosure mailing list is the source of the reported information.
Already a member? Log in here
