CVE-2026-15657: Foreup

Medium severity, CVSS 6.5. EPSS: 0.3% chance of exploitation in the next 30 days.

A vulnerability in the foreUP customer REST API allows any authenticated user to read cleartext payment-processor merchant credentials in the response body.

Affected products

Published 2026-07-30. Last modified 2026-07-31.