CVE-2026-5749Disclosure

LOWCVSS 8.7 · HIGH

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

Inadequate access control in the registration process in Fullstep V5, which could allow unauthenticated users to obtain a valid JWT token with which to interact with authenticated API resources. Successful exploitation of this vulnerability could allow an unauthenticated attacker to compromise the confidentiality of the affected resource, provided they have a valid token with which to interact with the API.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-306

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

STABLE

Threat summary

  • 3 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 2 signals
  • Disclosure: 3 classified signals
  • Peaked at 2 mentions on most recent observed day (2026-04-22)
  • 3 total mentions across 2 days

Deep dive

Activity timeline3 mentions / 2d
01122Mentions · 2026-04-20: 1Mentions · 2026-04-22: 2Technical Details · 2026-04-22: 204-2004-22
Signal classification1 categories
Disclosure
3100.0%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-04-201
Disclosure1
2026-04-222
Disclosure2
Full discourse3 posts
  • INCIBE-CERT@incibe_cert
    Disclosure

    ⚠️ #INCIBEaviso | Múltiples vulnerabilidades en #Fullstep #CVE CVE-2026-5749 CVE-2026-5750 https://www.incibe.es/incibe-cert/alerta-temprana/avisos/multiples-vulnerabilidades-en-fullstep #AvisosDeSeguridad #TI

    Post summary

    The text announces Incibe’s security advisory reporting multiple CVEs (CVE‑2026‑5749 and CVE‑2026‑5750) affecting Fullstep, without providing PoC details, exploit code, or evidence of active exploitation.

    01030477
    42.7K followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-5749 Inadequate access control in the registration process in Fullstep V5, which could allow unauthenticated users to obtain a valid JWT token with which to interact with au… https://www.cve.org/CVERecord?id=CVE-2026-5749

    Post summary

    The text announces CVE-2026-5749, noting inadequate access control in Fullstep V5's registration process that allows unauthenticated users to obtain a valid JWT token.

    00000160
    57.2K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-5749 Unauthenticated JWT Token Acquisition via Inadequate Access Control in Fullstep V5 https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-5749

    Post summary

    The post announces a newly identified unauthenticated JWT token acquisition flaw in Fullstep V5, providing a brief technical overview but lacking details on PoC, exploitation, or remediation.

    0000037
    4.0K followersView on X

Explore more