Access Control Flaw in Fullstep V5 Exposes Sensitive API Resources
CVE-2026-5749

8.7HIGH

Key Information:

Vendor

Fullstep

Status
Vendor
CVE Published:
22 April 2026

What is CVE-2026-5749?

An access control issue exists in Fullstep V5, allowing unauthenticated users to generate valid JWT tokens. This flaw may enable attackers to interact with protected API resources, potentially exposing confidential information. Effective remediation is necessary to ensure that sensitive data remains safeguarded against unauthorized access.

Affected Version(s)

Fullstep 5

Fullstep 5.30.07

References

CVSS V4

Score:
8.7
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Alejandro Rivera León
.