Remote User Creation Vulnerability in Web Application by Unknown Vendor
CVE-2026-14949

8.5HIGH

Key Information:

Status
Vendor
CVE Published:
20 August 2026

What is CVE-2026-14949?

A vulnerability exists within the web application allowing low privileged remote attackers with an authenticated session to manipulate the user creation endpoint. By sending specific requests to the /api/user/add.php endpoint, these attackers can create new user accounts with roles that may include the highest privilege level available in the application, leading to potential unauthorized access and control over sensitive functionalities.

Affected Version(s)

FDS 102 2.11.0 <= 2.13.3

References

CVSS V4

Score:
8.5
Severity:
HIGH
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.