Data Exposure Vulnerability in foreUP Customer REST API by foreUP
CVE-2026-15658

Currently unrated

Key Information:

Vendor

Foreup

Status
Vendor
CVE Published:
30 July 2026

What is CVE-2026-15658?

A vulnerability exists in the foreUP Customer REST API that permits authenticated low-privilege customers to access sensitive records belonging to other users. The flaw arises from the lack of proper access controls in the API's endpoint, enabling unauthorized data visibility and potentially leading to significant privacy breaches. This weakness emphasizes the critical need for robust authorization checks to ensure that users can only access their own data.

Affected Version(s)

foreUP API

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.