Remote User Creation Vulnerability in Web Application by Unknown Vendor
CVE-2026-14949
8.5HIGH
What is CVE-2026-14949?
A vulnerability exists within the web application allowing low privileged remote attackers with an authenticated session to manipulate the user creation endpoint. By sending specific requests to the /api/user/add.php endpoint, these attackers can create new user accounts with roles that may include the highest privilege level available in the application, leading to potential unauthorized access and control over sensitive functionalities.
Affected Version(s)
FDS 102 2.11.0 <= 2.13.3
