CVE 7.6 HIGH

Insecure direct object reference (IDOR) vulnerability in Fullstep_CVE-2026-5750

7.6 / 10
HIGH
CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N

Description

An insecure direct object reference (IDOR) vulnerability in the Fullstep V5 registration process allows authenticated users to access data belonging to other registered users through various vulnerable authenticated resources in the application. The vulnerable endpoints result from: '/api/suppliers/v1/suppliers//false' to list user information; and '/#/supplier-registration/supplier-registration//2' to update your user information (personal details, documents, etc.).

Basic Information

ID CVE-2026-5750
Source INCIBE
Published Apr 22, 2026 at 13:25
Modified Apr 22, 2026 at 13:59

Affected Product

Vendor Fullstep
Product Fullstep
Version 5
Affected Versions Fullstep Fullstep 5

CWE Classification

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.