CVE-2026-15657

Summary

A vulnerability in the foreUP customer REST API allows any authenticated user to read cleartext payment-processor merchant credentials in the response body.

Affected Software

VendorProductVersion RangeStatus
foreUPforeUPAPIaffected

Weaknesses

  • CWE-522: Insufficiently Protected Credentials

ADP Enrichment

CISA ADP Vulnrichment

  • SSVC:
  • Exploitation: none
    • Automatable: no
    • Technical Impact: partial

References