Executive brief
Omega Solution's FBP (Fulfillment by People) platform contains an authorization flaw in its user profile API that allows authenticated attackers to view other users' private information. An attacker can modify a URL parameter to access arbitrary user accounts and retrieve sensitive personal data including names, email addresses, phone numbers, physical addresses, and account status without proper permission checks.
Technical details
The User Profile API endpoint GET /user/{id} fails to validate whether an authenticated user has authorization to access the requested profile record. An attacker authenticated to the platform can enumerate or modify the {id} path parameter to retrieve data from any other user account. The vulnerability requires valid authentication credentials but no user interaction, and exposes confidential user information including PII.
Affected products
- Omega Solution FBP Fulfillment by People 2025
Timeline
- 2026-07-17: disclosed
- 2026-09-21: advisory