Sceawere
Vulnerability Detail
CVE-2026-97074UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
Omnisend IDOR Subscriber Data Exposure
Vulnerability Metadata
- Severity
- Medium
- Score / CVSS
- 4.3
- Creation Date
- 3h ago
- Vendor
- Omnisend
- Product
- Newsletters, Email Marketing, SMS and Popups by Omnisend
- Attack Type
- CWE-639 Authorization Bypass Through User-Controlled Key
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
- Attack Complexity
- LOW
Narrative and Response
Description
Subscriber Insecure Direct Object References (IDOR) in Newsletters, Email Marketing, SMS and Popups by Omnisend <= 1.9.0 versions.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "4.3",
"pubDate": "2026-09-30T13:17:34.340Z",
"pubdate": "2026-09-30T13:17:34.340Z",
"executiveSummary": "The 'Newsletters, Email Marketing, SMS and Popups by Omnisend' plugin, versions 1.9.0 and below, contains an Insecure Direct Object Reference (IDOR) vulnerability.\nThis vulnerability allows unauthenticated attackers to access sensitive subscriber data by manipulating identifiers within API requests.\nThe flaw impacts the confidentiality of the marketing database, potentially exposing email addresses, names, and other subscriber metadata managed through the plugin.\nThe issue arises from a failure to implement proper authorization checks on server-side endpoints responsible for retrieving subscriber information.\nSuccessful exploitation requires no prior authentication, as the application fails to validate whether the requester possesses the appropriate privileges to view the requested data objects.\nThe risk implication is significant for site owners, as unauthorized access to marketing databases can lead to data breaches, privacy compliance violations (such as GDPR), and targeted phishing campaigns against the exposed subscriber base.\nAttackers can systematically scrape the database by iterating through object identifiers if the system uses predictable or sequential resource keys.",
"technicalDetails": "The vulnerability resides in the internal API implementation within the Omnisend plugin suite, specifically affecting the data retrieval functions used for managing subscriber records.\nAn IDOR occurs when an application exposes a reference to an internal implementation object, such as a database key or resource ID, without performing an access control check to ensure the user is authorized to interact with that object.\nIn this specific instance, the plugin's endpoint accepts a user-controlled parameter, likely an integer ID or unique identifier representing a specific subscriber entry.\nBecause the server-side code performs a direct database lookup based on this identifier without verifying the session context or ownership of the record, the request is processed and the associated sensitive data is returned to the user.\nThe attack flow involves the following steps: First, the attacker identifies the vulnerable API endpoint through traffic analysis or reverse engineering the plugin's JavaScript files.\nSecond, the attacker crafts a malicious HTTP GET or POST request to the identified endpoint, appending the target identifier to the request URI or within the body payload.\nThird, the server interprets the request as legitimate, queries the backend database, and serializes the subscriber's information (including Personally Identifiable Information) into the response object.\nFourth, the attacker receives the response, allowing them to extract sensitive metadata. If the object IDs are sequential, the attacker can automate the exploitation process using a simple script to iterate through IDs, resulting in an unauthorized bulk download of the subscriber list.\nThe root cause is a deficiency in the authorization logic layer of the plugin, where it assumes that knowledge of a resource identifier equates to authorized access.\nThe vulnerability is present in versions 1.9.0 and earlier. It does not require any administrative or subscriber-level authentication to execute, effectively exposing the system to any network-capable actor who can reach the site's REST or custom API endpoints."
}