CyberRota Analysis
AI-GeneratedThe vulnerability in the foreUP customer REST API allows authenticated users to access cleartext payment-processor merchant credentials, potentially exposing sensitive financial information. Organizations utilizing this API should prioritize remediation to prevent unauthorized access to critical payment data. This is particularly relevant for businesses handling payment transactions or customer financial information.
CVE
CVE-2026-15657
Severity
MEDIUM
CVSS
6.5
EPSS
0.26%
Original NVD Description
A vulnerability in the foreUP customer REST API allows any authenticated user to read cleartext payment-processor merchant credentials in the response body.