Sceawere

Vulnerability Detail

CVE-2026-97074UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Omnisend IDOR Subscriber Data Exposure

Vulnerability Metadata

Severity
Medium
Score / CVSS
4.3
Creation Date
3h ago
Vendor
Omnisend
Product
Newsletters, Email Marketing, SMS and Popups by Omnisend
Attack Type
CWE-639 Authorization Bypass Through User-Controlled Key
Vector String
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
Attack Complexity
LOW

Narrative and Response

Description

Subscriber Insecure Direct Object References (IDOR) in Newsletters, Email Marketing, SMS and Popups by Omnisend <= 1.9.0 versions.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "4.3",
  "pubDate": "2026-09-30T13:17:34.340Z",
  "pubdate": "2026-09-30T13:17:34.340Z",
  "executiveSummary": "The 'Newsletters, Email Marketing, SMS and Popups by Omnisend' plugin, versions 1.9.0 and below, contains an Insecure Direct Object Reference (IDOR) vulnerability.\nThis vulnerability allows unauthenticated attackers to access sensitive subscriber data by manipulating identifiers within API requests.\nThe flaw impacts the confidentiality of the marketing database, potentially exposing email addresses, names, and other subscriber metadata managed through the plugin.\nThe issue arises from a failure to implement proper authorization checks on server-side endpoints responsible for retrieving subscriber information.\nSuccessful exploitation requires no prior authentication, as the application fails to validate whether the requester possesses the appropriate privileges to view the requested data objects.\nThe risk implication is significant for site owners, as unauthorized access to marketing databases can lead to data breaches, privacy compliance violations (such as GDPR), and targeted phishing campaigns against the exposed subscriber base.\nAttackers can systematically scrape the database by iterating through object identifiers if the system uses predictable or sequential resource keys.",
  "technicalDetails": "The vulnerability resides in the internal API implementation within the Omnisend plugin suite, specifically affecting the data retrieval functions used for managing subscriber records.\nAn IDOR occurs when an application exposes a reference to an internal implementation object, such as a database key or resource ID, without performing an access control check to ensure the user is authorized to interact with that object.\nIn this specific instance, the plugin's endpoint accepts a user-controlled parameter, likely an integer ID or unique identifier representing a specific subscriber entry.\nBecause the server-side code performs a direct database lookup based on this identifier without verifying the session context or ownership of the record, the request is processed and the associated sensitive data is returned to the user.\nThe attack flow involves the following steps: First, the attacker identifies the vulnerable API endpoint through traffic analysis or reverse engineering the plugin's JavaScript files.\nSecond, the attacker crafts a malicious HTTP GET or POST request to the identified endpoint, appending the target identifier to the request URI or within the body payload.\nThird, the server interprets the request as legitimate, queries the backend database, and serializes the subscriber's information (including Personally Identifiable Information) into the response object.\nFourth, the attacker receives the response, allowing them to extract sensitive metadata. If the object IDs are sequential, the attacker can automate the exploitation process using a simple script to iterate through IDs, resulting in an unauthorized bulk download of the subscriber list.\nThe root cause is a deficiency in the authorization logic layer of the plugin, where it assumes that knowledge of a resource identifier equates to authorized access.\nThe vulnerability is present in versions 1.9.0 and earlier. It does not require any administrative or subscriber-level authentication to execute, effectively exposing the system to any network-capable actor who can reach the site's REST or custom API endpoints."
}
CVE-2026-97074: Omnisend IDOR Subscriber Data Exposure (MEDIUM Severity, CVSS: 4.3) | Sceawere