VORANT. Threat Intelligence Sign in Get the full feed

foreUP golf software exposes payment credentials

medium vulnerability retail

Two API flaws in Golf Compete foreUP let any customer steal merchant payment credentials and other golfers' full profiles and payment tokens.

Golf Compete foreUP, a cloud-based golf course management platform used by over 2,000 facilities, contained two REST API vulnerabilities disclosed via CERT/CC. CVE-2026-15657 exposed cleartext Finix merchant API credentials (username, password, merchant ID) in every customer record response, with credentials shared across all customers at a facility. CVE-2026-15658 is a Broken Object Level Authorization (BOLA/IDOR) flaw allowing an authenticated user to substitute another customer's golfer_id in the request path to retrieve that customer's full profile, including PII, payment tokens, Dwolla bank funding-source tokens, and transaction history.

Chained together, these vulnerabilities allowed any low-privilege authenticated customer to enumerate other customers' data and extract facility-wide merchant payment processor credentials. Because the API is shared across tenants, a customer at one facility could access merchant credentials belonging to a completely different facility, expanding the blast radius across the entire platform's customer base. No authentication bypass or exploit development was required beyond a valid JWT and predictable identifier manipulation.

foreUP confirmed remediation of both issues on July 26, 2026. No evidence of active exploitation was reported; this is a responsibly disclosed vulnerability finding rather than an observed attack campaign. Affected users are advised to watch for phishing and identity theft attempts stemming from potential prior exposure of payment tokens and PII.

Mentioned in this report

Vulnerabilities CVE-2026-15657CVE-2026-15658

Source reporting: https://kb.cert.org/vuls/id/790363

This is the public brief

Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.

Start free