← Back to search

CVE-2026-94152

4.3 MEDIUMpublic exploit available

Published 2026-09-21 · Updated 2026-09-21

AI risk analysis

Summary
The flaw allows for authorization bypass through manipulation of the ID argument in the User Profile API, enabling unauthorized access to user data.
Exploitability
Exploitation requires control over the ID parameter and remote access; public exploits exist but may require specific conditions.
Blast radius
If exploited, this could lead to widespread unauthorized access to sensitive user information within affected systems.
Prioritized remediation
Apply vendor patches or updates as soon as available to address the vulnerability.
auth-bypassapiwebremote-exploitable

Analysis generated locally by qwen2.5:7b-instruct (no data left the box). AI-assisted — verify against primary sources before acting.

NVD description

A security vulnerability has been detected in Omega Solution FBP Fulfillment by People 2025. This impacts an unknown function of the file /user/ of the component User Profile API. The manipulation of the argument ID leads to authorization bypass. Remote exploitation of the attack is possible. The exploit has been disclosed publicly and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N

Weaknesses

CWE-285, CWE-639

Public exploit & PoC references

All references

Source data: NVD (nvd.nist.gov), public domain. Exploit-DB.ai adds local AI analysis for defensive use only.

Related CVEs

Related by shared AI tags and CWE weakness class. Browse the full archive.