SEPTEMBER 19, 2026
Live Feed
Back to database
Case File

CVE-2026-15657

MEDIUM · CVSS 6.5 EPSS 0.26%

Source: NVD + CISA KEV + EPSS · Published 2026-07-30 · Last synced 2026-08-29

CyberRota Analysis

AI-Generated

The vulnerability in the foreUP customer REST API allows authenticated users to access cleartext payment-processor merchant credentials, potentially exposing sensitive financial information. Organizations utilizing this API should prioritize remediation to prevent unauthorized access to critical payment data. This is particularly relevant for businesses handling payment transactions or customer financial information.

CVE
CVE-2026-15657
Severity
MEDIUM
CVSS
6.5
EPSS
0.26%

Original NVD Description

A vulnerability in the foreUP customer REST API allows any authenticated user to read cleartext payment-processor merchant credentials in the response body.