Security researcher reports reveal that Johnson & Johnson web applications contained critical vulnerabilities that exposed student data and internal audit records across twenty different corporate entities.
Key Points
- A campus recruiting portal vulnerability exposed personal details and interview notes for nearly 1,000 students due to improper API authentication.
- An internal Audit Tracking Management System (ATMS) allowed unauthorized administrative access, potentially exposing confidential meeting minutes and transcripts.
- Both systems relied on insecure client-side authentication logic that failed to validate Microsoft SSO tokens, allowing researchers to bypass login requirements.
- The researcher reported the flaws in October 2025, but the ATMS vulnerability remained unpatched until April 2026 following media intervention.
- The ATMS platform served as a centralized hub for sensitive data across twenty J&J subsidiaries, including Ethicon, Janssen, and Abiomed.