Sceawere

Vulnerability Detail

CVE-2026-94152UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Omega Solution FBP Authorization Bypass

Vulnerability Metadata

Severity
Medium
Score / CVSS
4.3
Creation Date
5h ago
Vendor
Omega Solution
Product
FBP Fulfillment by People
Attack Type
Authorization Bypass
Vector String
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Attack Complexity
LOW

Narrative and Response

Description

A security vulnerability has been detected in Omega Solution FBP Fulfillment by People 2025. This impacts an unknown function of the file /user/ of the component User Profile API. The manipulation of the argument ID leads to authorization bypass. Remote exploitation of the attack is possible. The exploit has been disclosed publicly and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "4.3",
  "pubDate": "2026-09-21T09:17:06.747Z",
  "pubdate": "2026-09-21T09:17:06.747Z",
  "executiveSummary": "A critical authorization bypass vulnerability has been identified in the Omega Solution FBP Fulfillment by People 2025 User Profile API.\nThe vulnerability resides within the '/user/' file and is triggered via the manipulation of the 'ID' argument, allowing unauthorized access to sensitive user data or functions.\nThe flaw allows remote attackers to bypass established security controls, potentially leading to unauthorized data exposure or account takeover.\nThe vulnerability is currently public, and given the vendor's lack of responsiveness, the risk profile is significantly elevated for organizations utilizing this software.\nSuccessful exploitation requires no specialized authentication or local access, as the vulnerability is remotely exploitable via the network.\nEntities operating this software face an immediate risk of information disclosure or unauthorized administrative actions due to the failure of the application's access control mechanisms.",
  "technicalDetails": "The vulnerability manifests as an Improper Authorization flaw within the User Profile API component of the Omega Solution FBP Fulfillment by People 2025 platform.\nThe root cause is a failure of the server-side logic to properly validate the session context against the requested 'ID' parameter during interactions with the '/user/' API endpoint.\nIn a standard implementation, an application should verify that the authenticated user possesses the appropriate permissions or ownership claims to access or modify resources associated with a specific user identifier provided in the URI or payload.\nIn this instance, the input 'ID' argument is not sufficiently anchored to the requestor's session object, allowing an attacker to supply arbitrary identifiers to access profile data belonging to other users or potentially elevated accounts.\nThe attack flow proceeds as follows: 1) The attacker initiates a request to the '/user/' endpoint. 2) The attacker injects a target user's 'ID' into the corresponding argument. 3) The backend application processes the request, failing to perform a secondary authorization check to ensure the requester is authorized to view or manipulate the object associated with the provided 'ID'. 4) The application returns the requested data or executes the requested function based on the attacker's supplied parameter, effectively bypassing intended security constraints.\nThe exploitation is remote and does not require pre-existing authentication, as the flaw resides at the entry point of the API interaction. By manipulating the 'ID' parameter, an attacker can bypass vertical and horizontal authorization boundaries.\nPost-exploitation, the impact is severe, potentially allowing for the exfiltration of personal identifiable information (PII), modification of user settings, or, depending on the scope of the underlying function, administrative takeover if the 'ID' relates to high-privileged accounts.\nSince the vulnerability is disclosed publicly and no vendor patch has been issued, there are no structural barriers to exploitation by malicious actors, and the attack surface remains fully exposed."
}
CVE-2026-94152: Omega Solution FBP Authorization Bypass (MEDIUM Severity, CVSS: 4.3) | Sceawere