CVE-2026-14953: CWE-425 Direct Request ('Forced Browsing') in Frauscher Sensortechnik FDS 102
Description
CVE-2026-14953 is a medium severity vulnerability in Frauscher Sensortechnik FDS 102 versions 2.11.0 through 2.13.3. It allows a low-privileged remote attacker to enumerate all configured users and determine which accounts have elevated privileges via the /api/user/fetch-all.php endpoint. This is a direct request (forced browsing) vulnerability categorized under CWE-425.
CVSS v4.0
Score 5.3medium
Affected software
Frauscher Sensortechnik
FDS 102
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
This vulnerability (CVE-2026-14953) affects Frauscher Sensortechnik FDS 102 versions >=2.11.0 and <=2.13.3. It enables a remote attacker with low privileges to access the /api/user/fetch-all.php endpoint to enumerate all user accounts and identify those with elevated privileges. The flaw is classified as CWE-425 (Direct Request or Forced Browsing), indicating insufficient access control on this API endpoint. The CVSS 4.0 base score is 5.3, reflecting medium severity with network attack vector, low complexity, no privileges required beyond low, and no user interaction needed.
Potential Impact
An attacker with low privileges can remotely enumerate all user accounts and identify which users have elevated privileges. This information disclosure can aid further targeted attacks or privilege escalation attempts. There is no indication of direct code execution or data modification from this vulnerability alone.
Mitigation Recommendations
No official patch or remediation has been provided in the available data. Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until a fix is available, restrict access to the /api/user/fetch-all.php endpoint to authorized users only, if possible, and monitor for suspicious access patterns.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- CERTVDE
- Date Reserved
- 2026-07-07T12:47:02.217Z
- Cvss Version
- 4.0
- State
- PUBLISHED
Threat ID: 6a86bcd9acd9273b495abbbe
Added to database: 08/20/2026, 08:37:45 UTC
Last enriched: 09/11/2026, 05:32:35 UTC
Last updated: 10/04/2026, 10:02:25 UTC
Views: 81
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.