Corporate Affairs Commission (CAC)
Electronic Document Management System
A document-retrieval path in the Commission's Electronic Document Management System served corporate records without verifying that the requester was entitled to them. Because document identifiers were sequential and no authorisation check stood in front of the response, the exposure was not limited to a single record. It was systemic.
WHAT WAS AT RISK
- Corporate registration and incorporation documents
- Identity documents belonging to company directors
- Signed corporate resolutions and constitutional documents
IMPACT IF EXPLOITED
Identity theft, corporate impersonation and business fraud at national scale, because the registry underpins company verification across the Nigerian economy.
DISCLOSURE TIMELINE
- 10 Dec 2025I report the finding to Nigeria's national CERT, with full technical detail supplied on request.
- 10 Dec 2025ngCERT opens incident ticket ngCERT/zJgH/2025 and begins investigation.
- 12 Dec 2025ngCERT confirms it successfully validated the vulnerability and commits to remediation of the affected endpoint.
I reported it alongside remediation guidance: authentication middleware on document routes, document-level access control lists, rate limiting, audit logging, and a wider review of the platform's session management.
- REPORTED
- 10 December 2025
- CHANNEL
- ngCERT (NCCC / ONSA)
- TICKET
- ngCERT/zJgH/2025
- VALIDATED
- 12 December 2025
- SCOPE
- 21M+ registered entities
- STATUS
- Validated, remediation committed