Session Handling Vulnerability in FDS Web Interface by Vendor Name
CVE-2026-14950
9.2CRITICAL
What is CVE-2026-14950?
The FDS Web Interface is susceptible to a session handling vulnerability that allows unauthenticated remote attackers to exploit active session identifiers. If an attacker gains access to a valid session token, they can continue to utilize the session even after it is supposed to have expired. This flaw raises significant concerns regarding the security of unattended, shared, or leaked sessions, leading to potential unauthorized access and manipulation of the web interface. Proper session termination and management protocols are critical to mitigate these risks.
Affected Version(s)
FDS 102 2.1.0 <= 2.13.3
