SEPTEMBER 20, 2026
Live Feed
Back to database
Case File

CVE-2026-15658

HIGH · CVSS 8.1 EPSS 0.26%

Source: NVD + CISA KEV + EPSS · Published 2026-07-30 · Last synced 2026-08-29

CyberRota Analysis

AI-Generated

A vulnerability in the foreUP customer REST API permits authenticated, low-privilege users to access endpoints that expose records belonging to other users, bypassing ownership verification. This could lead to unauthorized data exposure, impacting user privacy and potentially violating data protection regulations. Organizations utilizing this API should prioritize remediation to safeguard sensitive user information and maintain compliance.

CVE
CVE-2026-15658
Severity
HIGH
CVSS
8.1
EPSS
0.26%

Original NVD Description

A vulnerability in the foreUP customer REST API allows any authenticated, low-privilege customer to access an endpoint that returns the records of other users without checking that the caller owns the data associated with that record.