API Vulnerability in ForeUP Affects Payment Processor Credentials
CVE-2026-15657
Currently unrated
What is CVE-2026-15657?
A security flaw in the foreUP Customer REST API allows authenticated users to access sensitive payment-processor merchant credentials in cleartext within the response body. This vulnerability poses serious risks to data confidentiality, potentially enabling unauthorized users to exploit the information for malicious purposes. Organizations using this API should immediately assess their exposure and implement proper security measures to mitigate risks.
Affected Version(s)
foreUP API
