Threats Tagged 'cve-2026-14948'
View all threats tagged with 'cve-2026-14948'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'cve-2026-14948'
Click on any threat for detailed analysis and mitigation recommendations
A low privileged remote attacker can hijack an active administrative session without needing to know the administrator password by extracting live… (CVE-2026-14948)CVE-2026-14948 0 CVE-2026-14948 is a high-severity vulnerability that allows a low privileged remote attacker to hijack an active administrative session without knowing the administrator password. The attacker can extract live plaintext session identifiers from downloadable error log archives, enabling unauthorized access to authenticated sessions. Join the discussion | GCVE Database | 08/20/2026, 09:31:17 UTC Added: 08/20/2026, 14:08:19 UTC |
CVE-2026-14948: CWE-532 Insertion of Sensitive Information into Log File in Frauscher Sensortechnik FDS 102CVE-2026-14948 0 A low privileged remote attacker can hijack an active administrative session without needing to know the administrator password by extracting live plaintext session identifiers for authenticated users from downloadable error log archives. Join the discussion | CVE Database V5 | 08/20/2026, 08:19:00 UTC Added: 08/20/2026, 08:22:54 UTC |
CVE-2026-14946: CWE-434 Unrestricted Upload of File with Dangerous Type in Frauscher Sensortechnik FDS 102CVE-2026-14946 0 Successful exploitation of these vulnerabilities could allow attackers to execute arbitrary code on the FDS102 web server, write files to arbitrary server locations, hijack active administrative sessions, create privileged user accounts, perform unauthorized actions, access sensitive railway signalling and track layout information, and enumerate user accounts and privilege levels. The impact depends on the affected version and attacker privileges, but the combined issue set affects confidentiality, integrity, and availability of the FDS102 web interface and underlying system. Join the discussion | CVE Database V5 | 08/20/2026, 10:00:00 UTC Added: 08/20/2026, 08:22:54 UTC |
Showing 1 to 3 of 3 results