CVE-2026-15657

Severity CVSS v4.0:
Pending analysis
Type:
CWE-522 Insufficiently Protected Credentials
Publication date:
30/07/2026
Last modified:
31/07/2026

Description

A vulnerability in the foreUP customer REST API allows any authenticated user to read cleartext payment-processor merchant credentials in the response body.

References to Advisories, Solutions, and Tools