Unsafe object reference (IDOR) in Stel Order v3.25.1 and earlier versions, specifically in the ‘/app/FrontController’ endpoint, through manipulation of the ‘employeeID’ parameter. An authenticated attacker could exploit this vulnerability to access information about any employee (first names, last names, roles, job titles, and vacation records, among others) by modifying that identifier in requests sent to the server.
History

Thu, 14 May 2026 14:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 14 May 2026 13:00:00 +0000

Type Values Removed Values Added
Description Unsafe object reference (IDOR) in Stel Order v3.25.1 and earlier versions, specifically in the ‘/app/FrontController’ endpoint, through manipulation of the ‘employeeID’ parameter. An authenticated attacker could exploit this vulnerability to access information about any employee (first names, last names, roles, job titles, and vacation records, among others) by modifying that identifier in requests sent to the server.
Title Unsafe Object Reference (IDOR) vulnerability in Stel Order
First Time appeared Stel Order
Stel Order stel Order
Weaknesses CWE-639
CPEs cpe:2.3:a:stel_order:stel_order:*:*:*:*:*:*:*:*
Vendors & Products Stel Order
Stel Order stel Order
References
Metrics cvssV4_0

{'score': 7.1, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: INCIBE

Published:

Updated: 2026-05-14T13:48:15.193Z

Reserved: 2026-04-08T14:09:26.134Z

Link: CVE-2026-5798

cve-icon Vulnrichment

Updated: 2026-05-14T13:48:11.888Z

cve-icon NVD

Status : Received

Published: 2026-05-14T13:16:21.300

Modified: 2026-05-14T13:16:21.300

Link: CVE-2026-5798

cve-icon Redhat

No data.