October 8, 2026
Hardcoded API Key, 9,992 Leaked Employee Records, and an Unpatched CVE in Blue Yonder’s Public…
By Padmesh P S | Cybersecurity Researcher | 6 min read | Severity: High
By Padmesh
1 min read
Blue Yonder visited my college for campus placements. They build supply chain software used by Walmart, DHL, Tesco, and around half of Fortune 500. Before I engaged with them professionally, I did what I usually do. I looked at their infrastructure.
What started as surface-level recon turned into three reportable findings. All were disclosed responsibly. All were acknowledged.
Finding 1: Hardcoded API Key in a Public JS Bundle
Frontend bundles are underrated. Developers forget they are public-facing and secrets end up inside them constantly.
I pulled one of Blue Yonder's JavaScript bundles and scanned through it. Sitting inside was a Sitecore XM Cloud API key, hardcoded and unobfuscated.
Sitecore XM Cloud is their content management layer. With a valid API key you can authenticate to the management API. Depending on the permissions attached, that gives you read access to content, potential write access, and in some configurations access to delivery pipeline configuration.
The key was live at time of discovery , it was rotated now ngl.
Finding 2: GraphQL Introspection Exposing 9,992 Employee Records
Introspection should be disabled in production. It almost never is.
Blue Yonder had a GraphQL endpoint with introspection wide open. I ran a schema dump and got back 1,029 types. That volume tells you the API is complex and exposes a lot of internal models.
I queried a field called collateralOwner. Paginated through it. Got back 9,992 employee records - names, email addresses, job titles.
No authentication. No special headers. Just a query.
Finding 3: CVE-2024–46938, Unauthenticated File Read on Sitecore
This one had a CVE attached. I just needed to confirm it was exploitable on their instance.
CVE-2024–46938 is an unauthenticated file read in Sitecore. The vulnerable endpoint does not enforce authentication properly. If the instance is unpatched, you can read arbitrary files from the server.
Stage 1 confirmed. The endpoint responded. Stage 3, which would have involved reading web.config to extract the machine key, was blocked by their WAF.
The machine key matters because it signs ViewState in ASP.NET. With it, you can forge serialized payloads and get RCE. The WAF stopped me from completing the chain but the underlying vulnerability was live.
Disclosure
All findings were submitted through Blue Yonder's responsible disclosure program. No employee data was stored. The API key was only used to confirm it was active. I did not exploit beyond what was needed to verify each issue.
Everything was acknowledged by their security team.
This is all I can share on this one. They asked me not to disclose further details.