API Vulnerability in ForeUP Affects Payment Processor Credentials
CVE-2026-15657

Currently unrated

Key Information:

Vendor

Foreup

Status
Vendor
CVE Published:
30 July 2026

What is CVE-2026-15657?

A security flaw in the foreUP Customer REST API allows authenticated users to access sensitive payment-processor merchant credentials in cleartext within the response body. This vulnerability poses serious risks to data confidentiality, potentially enabling unauthorized users to exploit the information for malicious purposes. Organizations using this API should immediately assess their exposure and implement proper security measures to mitigate risks.

Affected Version(s)

foreUP API

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.