Description
A low privileged remote attacker with a valid session can submit a request to the user creation functionality exposed through /api/user/add.php to create new accounts with arbitrary role values, including the highest privilege level used by the application.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
No advisories yet.
References
| Link | Providers |
|---|---|
| https://www.certvde.com/en/advisories/VDE-2026-078/ |
|
History
Thu, 20 Aug 2026 08:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A low privileged remote attacker with a valid session can submit a request to the user creation functionality exposed through /api/user/add.php to create new accounts with arbitrary role values, including the highest privilege level used by the application. | |
| Title | Frauscher Sensortechnik: FDS102 for FAdC/FAdCi R2 is vulnerable to Incorrect Authorization due to improper enforcement of role-based access control | |
| First Time appeared |
Frauscher Sensortechnik
Frauscher Sensortechnik fds 102 |
|
| Weaknesses | CWE-863 | |
| CPEs | cpe:2.3:a:frauscher_sensortechnik:fds_102:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Frauscher Sensortechnik
Frauscher Sensortechnik fds 102 |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: CERTVDE
Published:
Updated: 2026-08-20T08:19:11.070Z
Reserved: 2026-07-07T12:46:58.350Z
Link: CVE-2026-14949
No data.
Status : Received
Published: 2026-08-20T09:16:47.307
Modified: 2026-08-20T09:16:47.307
Link: CVE-2026-14949
No data.
OpenCVE Enrichment
Updated: 2026-08-20T11:00:04Z
Weaknesses
-
CWE-863
Incorrect Authorization