CVE-2026-14949
8.5
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:N/SC:H/SI:H/SA:H
Summary
A low privileged remote attacker with a valid session can submit a request to the user creation functionality exposed through /api/user/add.php to create new accounts with arbitrary role values, including the highest privilege level used by the application.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Frauscher Sensortechnik | FDS 102 | 2.11.0 <= 2.13.3 | affected |
Weaknesses
- CWE-863: CWE-863 Incorrect Authorization
References
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.