Description
A low privileged remote attacker with a valid session can submit a request to the user creation functionality exposed through /api/user/add.php to create new accounts with arbitrary role values, including the highest privilege level used by the application.
Published: 2026-08-20
Score: 8.5 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Analysis and contextual insights are available on OpenCVE Cloud.

Remediation

No vendor fix or workaround currently provided.

Additional remediation guidance may be available on OpenCVE Cloud.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 20 Aug 2026 08:30:00 +0000

Type Values Removed Values Added
Description A low privileged remote attacker with a valid session can submit a request to the user creation functionality exposed through /api/user/add.php to create new accounts with arbitrary role values, including the highest privilege level used by the application.
Title Frauscher Sensortechnik: FDS102 for FAdC/FAdCi R2 is vulnerable to Incorrect Authorization due to improper enforcement of role-based access control
First Time appeared Frauscher Sensortechnik
Frauscher Sensortechnik fds 102
Weaknesses CWE-863
CPEs cpe:2.3:a:frauscher_sensortechnik:fds_102:*:*:*:*:*:*:*:*
Vendors & Products Frauscher Sensortechnik
Frauscher Sensortechnik fds 102
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N'}

cvssV4_0

{'score': 8.5, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:N/SC:H/SI:H/SA:H'}


Subscriptions

Frauscher Sensortechnik Fds 102
cve-icon MITRE

Status: PUBLISHED

Assigner: CERTVDE

Published:

Updated: 2026-08-20T08:19:11.070Z

Reserved: 2026-07-07T12:46:58.350Z

Link: CVE-2026-14949

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-08-20T09:16:47.307

Modified: 2026-08-20T09:16:47.307

Link: CVE-2026-14949

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-20T11:00:04Z

Weaknesses