IDOR Vulnerability in Fullstep V5 Registration Process Exposes User Data
CVE-2026-5750

7.6HIGH

Key Information:

Vendor

Fullstep

Status
Vendor
CVE Published:
22 April 2026

What is CVE-2026-5750?

In the Fullstep V5 system, an insecure direct object reference (IDOR) vulnerability has been identified within the registration process. This flaw permits authenticated users to gain unauthorized access to other users' data by exploiting several vulnerable authenticated resources. Specifically, endpoints such as '/api/suppliers/v1/suppliers//false' for listing user details and '/#/supplier-registration/supplier-registration//2' for updating personal information are susceptible. This exposure poses a significant risk to user privacy and data integrity.

Affected Version(s)

Fullstep 5

Fullstep 5.30.07

References

CVSS V4

Score:
7.6
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Alejandro Rivera León
.