bobdahacker.com Frontier Airlines Exposes Passenger Data for Over 100 Days
Article Content
- •Frontier Airlines exposed sensitive passenger data for over 100 days.
- •Scanning boarding pass barcodes can reveal full passport numbers and payment details.
- •The airline's API allows access to internal booking data with minimal authentication.
A significant security flaw in Frontier Airlines' booking system has exposed sensitive passenger data, including passport numbers, TSA PreCheck identifiers, and partial credit card details. The vulnerabilities have remained unaddressed for over 100 days, despite notification from ethical hacker 'bobdahacker.' Scanning the barcode on a boarding pass can reveal all this information, leaving customers vulnerable. The airline's mobile app API allows access to the complete internal booking object with just a PNR and last name. This breach affects all passengers using the airline's services, with serious implications for identity theft and fraud. Frontier Airlines has acknowledged potential IT vulnerabilities but claims they have been resolved. However, the lack of action on critical vulnerabilities raises concerns about their security posture.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (2)
Following this threat?
Track Frontier Airlines in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Critical Zero-Day Vulnerability in Cisco Secure Email Gateway Exploited On September 14, 2026, Cisco disclosed a critical SQL injection vulnerability (CVE-2026-76461) in its Secure Email Gateway, allowing unauthenticated remote attackers to execute arbitrary commands with root privileges. This vulnerability arises from insufficient validation in the email parsing logic. Cisco confirmed…
Critical WSO2 API Manager Vulnerability Under Active Exploitation A critical vulnerability (CVE-2026-5430) in WSO2 API Manager is being actively exploited, allowing unauthenticated attackers to forge admin tokens via JWT authentication bypass. This flaw, which has a CVSS score of 10.0, affects multiple WSO2 products including API Manager, Universal Gateway, Traffic Manager, and API…