Threats Tagged 'cve-2026-14949'
View all threats tagged with 'cve-2026-14949'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'cve-2026-14949'
Click on any threat for detailed analysis and mitigation recommendations
A low privileged remote attacker with a valid session can submit a request to the user creation functionality exposed through /api/user/add.php to create new accounts with arbitrary role values, including the highest privilege level used by the application. Join the discussion | GCVE Database | 08/20/2026, 08:19:11 UTC Added: 08/20/2026, 14:08:19 UTC |
CVE-2026-14949 is an authorization vulnerability in Frauscher Sensortechnik FDS 102 that allows a low privileged remote attacker with a valid session to create new user accounts with arbitrary roles, including the highest privilege level. This flaw exists in the user creation functionality exposed via /api/user/add.php. The vulnerability affects versions from 2.11.0 up to and including 2.13.3. The CVSS 4.0 base score is 8.5, indicating high severity. Join the discussion | CVE Database V5 | 08/20/2026, 08:19:11 UTC Added: 08/20/2026, 08:22:54 UTC |
0 CVE-2026-14946 is a high-severity vulnerability in Frauscher Sensortechnik FDS 102 that allows a high privileged remote attacker to upload a .php file due to improper file type validation. This uploaded file can then be accessed directly to execute arbitrary code, potentially leading to full system compromise. The affected versions include 2.8.0 through 2.13.3. No patch or remediation information is currently provided. Join the discussion | CVE Database V5 | 08/20/2026, 08:18:37 UTC Added: 08/20/2026, 08:22:54 UTC |
Showing 1 to 3 of 3 results