CVE-2026-15658: Foreup

High severity, CVSS 8.1. EPSS: 0.4% chance of exploitation in the next 30 days.

A vulnerability in the foreUP customer REST API allows any authenticated, low-privilege customer to access an endpoint that returns the records of other users without checking that the caller owns the data associated with that record.

Affected products

Published 2026-07-30. Last modified 2026-07-31.