# Insecure Dava India Pharmacy APIs Exposed Super Admin Users and Enabled Privileged Account Creation

DevFeed: [Insecure Dava India Pharmacy APIs Exposed Super Admin Users and Enabled Privileged Account Creation](<https://devfeed.tech/articles/hacking-a-pharmacy-to-get-free-prescription-drugs-and-more-32619.md>)

Original publisher: [Read original article](<https://eaton-works.com/2026/02/13/dava-india-hack/>)

Author: Eaton

Published: 2026-02-14T03:07:20Z

Content type: article

Language: en

Sources: [Eaton Works Feed](<https://devfeed.tech/sources/eaton-works-feed.md>)

Topics: [Exploit](<https://devfeed.tech/topics/exploit.md>), [Hacking](<https://devfeed.tech/topics/hacking.md>), [Website](<https://devfeed.tech/topics/website.md>), [account](<https://devfeed.tech/topics/account.md>), [password reset](<https://devfeed.tech/topics/password-reset.md>), [passwords](<https://devfeed.tech/topics/passwords.md>), [Next.js](<https://devfeed.tech/topics/next-js.md>)

Tags: [account](<https://devfeed.tech/tags/account.md>), [exploit](<https://devfeed.tech/tags/exploit.md>), [hacking](<https://devfeed.tech/tags/hacking.md>), [next-js](<https://devfeed.tech/tags/next-js.md>), [password](<https://devfeed.tech/tags/password.md>), [website](<https://devfeed.tech/tags/website.md>)

## AI overview

A security write-up describes insecure super-admin APIs on Dava India Pharmacy's website. The APIs exposed a list of super-admin users without authentication, and testing indicated that creating a super-admin account was a supported operation.

## Source excerpt

Super admin exploit on Dava India Pharmacy's website gave complete control over everything.