Description
A low privileged remote attacker with a valid session can submit a request to the user creation functionality exposed through /api/user/add.php to create new accounts with arbitrary role values, including the highest privilege level used by the application.
Published: 2026-08-20
Score: 8.5 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A low‑privileged attacker who has a valid session can send a request to the /api/user/add.php endpoint and create new accounts with arbitrary role values, including the highest privilege level used by the application. This incorrect authorization flaw, classified as CWE‑863, allows attackers to elevate privileges, potentially compromising confidentiality, integrity, and availability of the system.

Affected Systems

Frauscher Sensortechnik’s FDS 102 platform is affected. No specific versions were identified in the available data, so all releases of this product should be considered vulnerable unless a patch has been applied.

Risk and Exploitability

The vulnerability carries a CVSS score of 8.5, indicating high severity. The EPSS score of less than 1% suggests a low probability of exploitation in the short term, and the issue is not listed in the CISA Known Exploited Vulnerabilities catalog. Nonetheless, the attack can be carried out remotely over the network by any user with a low‑privileged account that can access the exposed endpoint, allowing the attacker to generate accounts with the highest level of access.

Generated by OpenCVE AI on August 20, 2026 at 22:13 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the vendor’s patch or update that corrects role‑based access control enforcement in the user creation endpoint.
  • Restrict or disable access to /api/user/add.php for non‑administrator accounts and enforce that only privileged users can assign role values.
  • Audit existing user accounts to eliminate any unauthorized high‑privilege accounts that may already exist.

Generated by OpenCVE AI on August 20, 2026 at 22:13 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 21 Aug 2026 22:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 20 Aug 2026 08:30:00 +0000

Type Values Removed Values Added
Description A low privileged remote attacker with a valid session can submit a request to the user creation functionality exposed through /api/user/add.php to create new accounts with arbitrary role values, including the highest privilege level used by the application.
Title Frauscher Sensortechnik: FDS102 for FAdC/FAdCi R2 is vulnerable to Incorrect Authorization due to improper enforcement of role-based access control
First Time appeared Frauscher Sensortechnik
Frauscher Sensortechnik fds 102
Weaknesses CWE-863
CPEs cpe:2.3:a:frauscher_sensortechnik:fds_102:*:*:*:*:*:*:*:*
Vendors & Products Frauscher Sensortechnik
Frauscher Sensortechnik fds 102
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N'}

cvssV4_0

{'score': 8.5, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:N/SC:H/SI:H/SA:H'}


Subscriptions

Frauscher Sensortechnik Fds 102
cve-icon MITRE

Status: PUBLISHED

Assigner: CERTVDE

Published:

Updated: 2026-08-21T21:47:44.069Z

Reserved: 2026-07-07T12:46:58.350Z

Link: CVE-2026-14949

cve-icon Vulnrichment

Updated: 2026-08-21T21:38:50.839Z

cve-icon NVD

Status : Deferred

Published: 2026-08-20T09:16:47.307

Modified: 2026-09-03T16:57:26.583

Link: CVE-2026-14949

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-20T22:15:04Z

Weaknesses