IDOR Vulnerability in Fullstep V5 Registration Process Exposes User Data
CVE-2026-5750
7.6HIGH
What is CVE-2026-5750?
In the Fullstep V5 system, an insecure direct object reference (IDOR) vulnerability has been identified within the registration process. This flaw permits authenticated users to gain unauthorized access to other users' data by exploiting several vulnerable authenticated resources. Specifically, endpoints such as '/api/suppliers/v1/suppliers//false' for listing user details and '/#/supplier-registration/supplier-registration//2' for updating personal information are susceptible. This exposure poses a significant risk to user privacy and data integrity.
Affected Version(s)
Fullstep 5
Fullstep 5.30.07
