
Klaviyo, the US‑based marketing automation service, recently disclosed a security flaw that allowed advertisers to see other users’ passwords. The issue stemmed from a mis‑configured API response that was unintentionally rendered on the advertiser dashboard, exposing login credentials for accounts that shared the same organization.
According to the company’s investigation, the bug appeared when multiple advertisers accessed the same Klaviyo workspace. While creating or editing a campaign, a background script fetched data meant for internal use only. Instead of being filtered out, the script displayed the raw authentication payload, which included the hashed password field. As a result, dozens of advertisers could potentially view passwords belonging to other marketers.
Klaviyo’s engineering team acted quickly: they rolled out a hot‑fix within hours, removed the vulnerable endpoint, and forced a password reset for all affected accounts. Users were also urged to enable two‑factor authentication (2FA) and to adopt strong, unique passwords across all services.
The incident highlights a broader challenge for SaaS platforms that support multi‑user environments. When many parties share a single workspace, strict data isolation is essential. Security experts advise businesses to regularly audit third‑party tools, enforce least‑privilege access, and conduct periodic penetration testing.
For Klaviyo customers, the immediate steps are clear: change your password immediately, enable 2FA, and review any recent activity for suspicious logins. In the longer term, organizations should implement password managers to generate and store complex credentials, reducing the risk of reuse across platforms. While the bug has been patched, the episode serves as a reminder that even leading tech providers can experience critical lapses, and proactive security hygiene remains the best defense.
Source: TechCrunch
Klaviyo Bug Exposes User Passwords to Advertisers
Yorum Yaz