Executive brief
Fullstep V5, a business consulting and procurement platform, contains a security flaw in its user registration process. This vulnerability allows unauthorized individuals to bypass security checks and obtain a valid digital access token. With this token, an attacker can access private company data and interact with internal systems as if they were a legitimate user, potentially leading to a significant breach of confidential information.
Technical details
A missing authentication vulnerability (CWE-306) exists in the registration workflow of Fullstep V5. The flaw allows an unauthenticated remote attacker to bypass access controls and generate a valid JSON Web Token (JWT). This token can subsequently be used to authenticate against various API endpoints that should be restricted to authorized users. Successful exploitation grants the attacker the ability to query sensitive data and interact with authenticated resources, compromising the confidentiality of the platform. The issue has been addressed in version 5.30.07.
Affected products
- Fullstep Fullstep V5 Prior to 5.30.07
Timeline
- 2026-01-29: patched: Version 5.30.07 available in production
- 2026-04-20: advisory: Initial advisory by INCIBE-CERT
- 2026-04-22: disclosed: CVE published to NVD