Access Control Flaw in Fullstep V5 Exposes Sensitive API Resources
CVE-2026-5749
8.7HIGH
What is CVE-2026-5749?
An access control issue exists in Fullstep V5, allowing unauthenticated users to generate valid JWT tokens. This flaw may enable attackers to interact with protected API resources, potentially exposing confidential information. Effective remediation is necessary to ensure that sensitive data remains safeguarded against unauthorized access.
Affected Version(s)
Fullstep 5
Fullstep 5.30.07
