Impact
A missing authorization check in the administrative API endpoint of CAXperts UPVWebServices and UDiTH Portal allows an authenticated user to deactivate the application’s license. The flaw is an elevation of privilege (CWE-862) and can cause the applications to become inoperable or require re‑licensing, effectively denying service to legitimate users.
Affected Systems
The affected products are CAXperts UPVWebServices versions 2.4.2212.603 through 2.7.6 and UDiTH Portal versions 2026.0.0 through 2026.2.0. These systems are used where the licensing mechanism is essential for operation.
Risk and Exploitability
The flaw requires a valid authenticated account; the attacker must first log in. Based on the description, the privilege escalation likely occurs via the intended administrative HTTP endpoint, a remote attack vector that we infer. The EPSS score of less than 1% suggests a low but non‑zero exploitation probability, while the CVSS score of 8.1 indicates high severity. The vulnerability is not listed in the CISA KEV catalog.
OpenCVE Enrichment