PatchSiren

Fullstep CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

HIGH Fullstep CVE published 2026-04-22

CVE-2026-5749

## Summary CVE-2026-5749 is a HIGH severity (CVSS 4.0: 8.7) authentication bypass vulnerability in Fullstep V5. The registration process fails to enforce proper access controls, allowing unauthenticated attackers to obtain valid JWT tokens and subsequently access authenticated API resources. The vulnerability was published on 2026-04-22 and last modified on 2026-05-19. ## Technical Details The root cause [truncated]