Data Exposure Vulnerability in foreUP Customer REST API by foreUP
CVE-2026-15658
Currently unrated
What is CVE-2026-15658?
A vulnerability exists in the foreUP Customer REST API that permits authenticated low-privilege customers to access sensitive records belonging to other users. The flaw arises from the lack of proper access controls in the API's endpoint, enabling unauthorized data visibility and potentially leading to significant privacy breaches. This weakness emphasizes the critical need for robust authorization checks to ensure that users can only access their own data.
Affected Version(s)
foreUP API
