CVE-2026-5798

Unsafe object reference (IDOR) in Stel Order v3.25.1 and earlier versions, specifically in the ‘/app/FrontController’ endpoint, through manipulation of the ‘employeeID’ parameter. An authenticated attacker could exploit this vulnerability to access information about any employee (first names, last names, roles, job titles, and vacation records, among others) by modifying that identifier in requests sent to the server.
CVSS

No CVSS.

Configurations

No configuration.

History

14 May 2026, 13:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-05-14 13:16

Updated : 2026-05-14 16:46


NVD link : CVE-2026-5798

Mitre link : CVE-2026-5798

CVE.ORG link : CVE-2026-5798


JSON object : View

Products Affected

No product.

CWE
CWE-639

Authorization Bypass Through User-Controlled Key