CVE-2026-15658
foreUP customer REST API allows unauthenticated endpoint access
CVSS Score
8.1
EPSS Score
0.1%
EPSS Percentile
3th
A vulnerability in the foreUP customer REST API allows any authenticated, low-privilege customer to access an endpoint that returns the records of other users without checking that the caller owns the data associated with that record.
| Vendor | foreup |
| Product | foreup |
| Published | Jul 30, 2026 |
| Last Updated | Jul 31, 2026 |
Stay Ahead of the Next One
Get instant alerts for foreup foreup
Be the first to know when new high vulnerabilities affecting foreup foreup are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
foreUP / foreUP
API