← Back to feed
Vulnerabilities & PatchesEmerging1 sourceJul 30, 2026 · 15:12via CERT/CC Vulnerability Notes

VU#790363: foreUP golf management platform's web API contains multiple vulnerabilities

Brief

Overview

Two vulnerabilities in the REST API were found in Golf Compete foreUP. The first exposes the merchant, Finix, API credentials directly in customer record responses, allowing any user to obtain and use the payment processor account.

The second is a missing object-level authorization check, which lets a user retrieve any other customer's full profile, payment token, and transaction history by changing the golfer_id in the request path.

Description

Golf Compete foreUP provides cloud-based golf course management software to over 2,000 golf courses. They offer tools that allow the management of customers, inventory, tee times, food & beverages, marketing, billing, etc. The vulnerabilities identified are listed below.

CVE-2026-15657 A vulnerability in the foreUP customer REST API exposes merchant credentials.

Read more on CERT/CC Vulnerability Notes