A low privileged remote attacker with a valid session can submit a request to the user creation functionality exposed through /api/user/add.php to create new accounts with arbitrary role values, including the highest privilege level used by the application.
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
| Link | Providers |
|---|---|
| https://www.certvde.com/en/advisories/VDE-2026-078/ |
|
History
Thu, 20 Aug 2026 08:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A low privileged remote attacker with a valid session can submit a request to the user creation functionality exposed through /api/user/add.php to create new accounts with arbitrary role values, including the highest privilege level used by the application. | |
| Title | Frauscher Sensortechnik: FDS102 for FAdC/FAdCi R2 is vulnerable to Incorrect Authorization due to improper enforcement of role-based access control | |
| First Time appeared |
Frauscher Sensortechnik
Frauscher Sensortechnik fds 102 |
|
| Weaknesses | CWE-863 | |
| CPEs | cpe:2.3:a:frauscher_sensortechnik:fds_102:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Frauscher Sensortechnik
Frauscher Sensortechnik fds 102 |
|
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: CERTVDE
Published:
Updated: 2026-08-20T08:19:11.070Z
Reserved: 2026-07-07T12:46:58.350Z
Link: CVE-2026-14949
No data.
Status : Received
Published: 2026-08-20T09:16:47.307
Modified: 2026-08-20T09:16:47.307
Link: CVE-2026-14949
No data.
OpenCVE Enrichment
No data.
Weaknesses