CVE-2025-55886

Medium severity, CVSS 6.5. EPSS: 0.4% chance of exploitation in the next 30 days.

An Insecure Direct Object Reference (IDOR) vulnerability was discovered in ARD. The flaw exists in the `fe_uid` parameter of the payment history API endpoint. An authenticated attacker can manipulate this parameter to access the payment history of other users without authorization.

Published 2025-09-22. Last modified 2026-06-17.