rootpwn

medium · CVSS v3 4.3 · CVSS v4 5.3 · EPSS 0.00218

CVE-2026-94152

CVE-2026-94152 is an authorization bypass vulnerability in Omega Solution FBP Fulfillment by People 2025’s User Profile API. By manipulating

Overview

CVE-2026-94152 is an authorization bypass vulnerability in Omega Solution FBP Fulfillment by People 2025’s User Profile API. By manipulating the ID parameter in the /user/ endpoint, an attacker can gain unauthorized access to user data. The flaw is exploitable remotely and has been publicly disclosed.

Description

A security vulnerability has been detected in Omega Solution FBP Fulfillment by People 2025. This impacts an unknown function of the file /user/ of the component User Profile API. The manipulation of the argument ID leads to authorization bypass. Remote exploitation of the attack is possible. The exploit has been disclosed publicly and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

Impact

The vulnerability allows attackers to bypass authorization controls, potentially exposing sensitive user information and compromising data integrity. Defenders should be aware that attackers could read or modify user profiles without proper authentication. This could lead to privacy violations and unauthorized data manipulation. The impact is limited to confidentiality and integrity of user data.

Remediation

Apply the vendor’s patch or update to the latest version of FBP Fulfillment that addresses the ID parameter validation in the User Profile API. If a patch is not available, implement network segmentation to restrict access to the /user/ endpoint and enforce strict authentication checks at the API gateway. Monitor logs for anomalous ID parameter usage and block suspicious requests.

Risk context

With a medium severity rating (CVSS 4.3) and a low EPSS score of 0.00218, the risk is moderate but still actionable. The public disclosure and remote exploitation potential warrant timely remediation. Defenders should prioritize patching or mitigation to prevent potential unauthorized access.

Affected products

  • Omega Solution FBP Fulfillment by People 2025

Scores

Severity
medium
CVSS v2
4
CVSS v3
4.3
CVSS v4
5.3
EPSS
0.00218

authorization-bypass remote-exploitation API user-profile medium-severity EPSS-low

← All CVEs