VulnerabilitiesHIGH

Vulnerabilities - UK Companies House Exposes Private Director Data

🎯

Basically, a flaw let people see private information about company directors for five months.

Quick Summary

A major flaw in the UK’s Companies House WebFiling service exposed private director data for five months. This breach raises serious concerns for registered businesses. Companies House is urging all affected to review their records for unauthorized changes.

What Happened

The UK’s Companies House, the official register of businesses, has disclosed a significant security flaw in its WebFiling service. This vulnerability exposed sensitive information about company directors for approximately five months. On March 16, 2026, Andy King, Chief Executive of Companies House, confirmed the incident. The flaw was discovered on March 13, leading to the immediate shutdown of the WebFiling system for repairs.

The issue stemmed from an Insecure Direct Object Reference (IDOR) vulnerability. This allowed logged-in users to access and modify another company's profile without permission. Although the flaw was not available to the general public, it posed serious risks to the integrity of company records.

Who's Affected

The breach primarily affects registered businesses and their directors. Sensitive data exposed includes dates of birth, private residential addresses, and registered company email addresses. While the vulnerability did not compromise passwords or highly sensitive identity verification documents, it still raises concerns about the potential for unauthorized filings.

Companies House is currently analyzing internal data logs to identify any unauthorized access during the exposure period. Although there are no confirmed reports of malicious exploitation, the agency is taking this incident seriously and will pursue strict actions against any misuse.

What Data Was Exposed

The vulnerability allowed attackers to view or alter records one at a time. This means that while large-scale data extraction was not possible, the potential for individual record manipulation existed. The exposed data is typically hidden from the public register, making this breach particularly concerning for affected individuals.

In addition to personal information, the flaw could have enabled unauthorized users to submit fraudulent filings. This means an attacker could potentially alter director details or file fake accounts on behalf of another business, leading to severe implications for the integrity of company records.

What You Should Do

In response to the breach, Companies House has reported the incident to the Information Commissioner’s Office (ICO) and the National Cyber Security Centre (NCSC). They are advising all registered businesses to log into their accounts immediately to review their registered details and filing history for any unauthorized changes.

If any suspicious activity is detected, businesses are encouraged to raise an official complaint with Companies House and provide evidence of the unauthorized changes. The agency is also preparing a detailed FAQ page to address concerns from business owners and cybersecurity professionals. This incident highlights the importance of regular security audits and vigilance in monitoring company records.

🔒 Pro insight: The IDOR vulnerability underscores the need for robust access controls in web applications to prevent unauthorized data exposure.

Original article from

Cyber Security News · Abinaya

Read Full Article

Related Pings

HIGHVulnerabilities

AWS Bedrock AgentCore - Critical Sandbox Bypass Vulnerability

A serious flaw in AWS Bedrock's Sandbox mode allows attackers to create covert C2 channels and exfiltrate sensitive data. Users must transition to VPC mode for better security.

Cyber Security News·
HIGHVulnerabilities

Vulnerability - UK Companies House Exposed Millions of Firms

A critical vulnerability at Companies House exposed sensitive data of millions of firms. This flaw allowed unauthorized access to company records, raising significant data protection concerns. Companies are urged to verify their details and report any issues.

SecurityWeek·
HIGHVulnerabilities

Spring AI Vulnerabilities - Security Advisory Released

Spring issued a security advisory for vulnerabilities in Spring AI software. Users must update to avoid serious risks from SQL and JSONPath injections. Timely action is essential for security.

Canadian Cyber Centre Alerts·
HIGHVulnerabilities

Cisco SD-WAN Vulnerability - High-Severity Flaw Ignored

A new warning reveals a high-severity flaw in Cisco SD-WAN that many security teams are missing. This oversight could lead to serious vulnerabilities for organizations. Immediate action is essential to safeguard networks against potential exploitation.

Cybersecurity Dive·
HIGHVulnerabilities

Angular XSS Vulnerability - Exposes Thousands of Web Apps

A critical XSS vulnerability in Angular has been discovered, affecting thousands of web applications. This flaw allows attackers to inject harmful scripts, risking user data and sessions. Developers must act quickly to patch their applications or implement strict data sanitization measures.

Cyber Security News·
MEDIUMVulnerabilities

Windows 11 Bluetooth Visibility Bug - Update Released

Microsoft has rolled out a fix for a Bluetooth visibility issue in Windows 11. Users can now manage their Bluetooth devices without hassle. This update is crucial for maintaining productivity with wireless peripherals. Ensure your system is updated to enjoy seamless connectivity.

Cyber Security News·