{"vuid":"VU#790363","idnumber":"790363","name":"foreUP golf management platform's web API contains multiple vulnerabilities","keywords":null,"overview":"### Overview\r\nTwo vulnerabilities in the REST API were found in Golf Compete foreUP. The first exposes the merchant, Finix, API credentials directly in customer record responses, allowing any user to obtain and use the payment processor account. The second is a missing object-level authorization check, which lets a user retrieve any other customer's full profile, payment token, and transaction history by changing the `golfer_id` in the request path. \r\n\r\n### Description\r\nGolf Compete foreUP provides cloud-based golf course management software to over 2,000 golf courses. They offer tools that allow the management of customers, inventory, tee times, food & beverages, marketing, billing, etc. The vulnerabilities identified are listed below.\r\n\r\n**CVE-2026-15657** A vulnerability in the foreUP customer REST API exposes merchant credentials. Each customer record response includes the facility’s merchant API credentials in cleartext, exposing the following details:\r\n\r\n* finix_username\r\n* finix_password\r\n* finix_merchant_id\r\n\r\nMerchant credentials are identical across for customers at the same facility and are actively used by the backend to register new payment instruments. Any authenticated customer can obtain the facility’s merchant credentials when querying own record. Combined with the second vulnerability described below, an attacker can retrieve merchant credentials from any customer record at the facility.\r\n\r\n**CVE-2026-15658** A missing object-level authorization also known as BOLA (Broken Object Level Authorization) and IDOR (Insecure Direct Object References) in the REST API endpoint returns the record identified by `golfer_id` without verifying ownership. A caller can substitute any `golfer_id` while using their own valid JSON Web Token (JWT) and receive another customer's full profile, including the following details:\r\n\r\n* Name, email, phone numbers, date of birth, address\r\n* Free‑text household relationship notes\r\n* Finix payment‑instrument tokens\r\n* Dwolla bank funding‑source tokens\r\n* Billing and transaction history\r\n\r\n### Impact\r\nWith a single valid low‑privilege foreUP customer account, someone can perform the following actions:\r\n1. Retrieve any customer’s full profile and contact data\r\n2. Access stored card tokens and Dwolla ACH funding-source tokens\r\n3. Enumerate and view full billing and transaction history for any customer\r\n4. Obtain live Finix merchant API credentials for the facility\r\n\r\nAlso, because the web API is shared by all tenants, all facilities using foreUP are affected, meaning that a customer from facility A could query merchant information from facility B.\r\n\r\n### Solution\r\nOn 07/26/2026, foreUP confirmed that all vulnerabilities in this report have been remediated. Users should remain aware of increased phishing and identity theft risks and monitor their accounts for suspicious activity.\r\n\r\n### Acknowledgements\r\nThank you to Eric Mead for reporting this vulnerability. This document was written by Bob Kemerer.","clean_desc":null,"impact":null,"resolution":null,"workarounds":null,"sysaffected":null,"thanks":null,"author":null,"public":["https://owasp.org/API-Security/editions/2023/en/0xa1-broken-object-level-authorization/","https://owasp.org/www-project-web-security-testing-guide/latest/4-Web_Application_Security_Testing/12-API_Testing/02-API_Broken_Object_Level_Authorization","https://portswigger.net/web-security/access-control/idor","https://owasp.org/www-project-web-security-testing-guide/latest/4-Web_Application_Security_Testing/05-Authorization_Testing/04-Testing_for_Insecure_Direct_Object_References"],"cveids":["CVE-2026-15658","CVE-2026-15657"],"certadvisory":null,"uscerttechnicalalert":null,"datecreated":"2026-07-30T15:12:59.583759Z","publicdate":"2026-07-30T15:12:59.447608Z","datefirstpublished":"2026-07-30T15:12:59.599995Z","dateupdated":"2026-07-30T15:12:59.447604Z","revision":1,"vrda_d1_directreport":null,"vrda_d1_population":null,"vrda_d1_impact":null,"cam_widelyknown":null,"cam_exploitation":null,"cam_internetinfrastructure":null,"cam_population":null,"cam_impact":null,"cam_easeofexploitation":null,"cam_attackeraccessrequired":null,"cam_scorecurrent":null,"cam_scorecurrentwidelyknown":null,"cam_scorecurrentwidelyknownexploited":null,"ipprotocol":null,"cvss_accessvector":null,"cvss_accesscomplexity":null,"cvss_authentication":null,"cvss_confidentialityimpact":null,"cvss_integrityimpact":null,"cvss_availabilityimpact":null,"cvss_exploitablity":null,"cvss_remediationlevel":null,"cvss_reportconfidence":null,"cvss_collateraldamagepotential":null,"cvss_targetdistribution":null,"cvss_securityrequirementscr":null,"cvss_securityrequirementsir":null,"cvss_securityrequirementsar":null,"cvss_basescore":null,"cvss_basevector":null,"cvss_temporalscore":null,"cvss_environmentalscore":null,"cvss_environmentalvector":null,"metric":null,"vulnote":228}