CVE-2026-15657
foreUP customer REST API allows authenticated users to read cleartext payment-processor merchant credentials
CVSS Score
6.5
EPSS Score
0.1%
EPSS Percentile
3th
A vulnerability in the foreUP customer REST API allows any authenticated user to read cleartext payment-processor merchant credentials in the response body.
| Vendor | foreup |
| Product | foreup |
| Published | Jul 30, 2026 |
| Last Updated | Jul 31, 2026 |
Stay Ahead of the Next One
Get instant alerts for foreup foreup
Be the first to know when new medium vulnerabilities affecting foreup foreup are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
foreUP / foreUP
API