Junglewise Threat Intelligence

CVE-2026-94152: Omega Solution FBP authorization bypass in User Profile API

CVE-2026-94152 · Severity: medium · CVSS 4.3 · Published 2026-09-21

Executive brief

Omega Solution's FBP (Fulfillment by People) platform contains an authorization flaw in its user profile API that allows authenticated attackers to view other users' private information. An attacker can modify a URL parameter to access arbitrary user accounts and retrieve sensitive personal data including names, email addresses, phone numbers, physical addresses, and account status without proper permission checks.

Technical details

The User Profile API endpoint GET /user/{id} fails to validate whether an authenticated user has authorization to access the requested profile record. An attacker authenticated to the platform can enumerate or modify the {id} path parameter to retrieve data from any other user account. The vulnerability requires valid authentication credentials but no user interaction, and exposes confidential user information including PII.

Affected products

  • Omega Solution FBP Fulfillment by People 2025

Timeline

  • 2026-07-17: disclosed
  • 2026-09-21: advisory

References