Authorization Bypass Vulnerability in Omega Solution FBP Fulfillment by People 2025
CVE-2026-94152
Key Information:
- Vendor
Omega Solution
- Vendor
- CVE Published:
- 21 September 2026
Badges
What is CVE-2026-94152?
A significant security flaw has been identified in Omega Solution's FBP Fulfillment by People 2025, specifically within the User Profile API component. This vulnerability arises from improper handling of the user ID argument, which can facilitate an unauthorized access scenario. Attackers can exploit this vulnerability remotely, allowing them to bypass authorization mechanisms. Despite notifications to the vendor regarding this issue, no response has been received. This situation raises concerns about the potential for exploitation in live environments, as the details of the vulnerability are currently public.
Affected Version(s)
FBP Fulfillment by People 2025
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved
