User Enumeration Vulnerability in Remote Access Applications by CERTVDE
CVE-2026-14953
5.3MEDIUM
What is CVE-2026-14953?
A vulnerability exists in certain remote access applications where a low-privileged remote attacker can exploit the endpoint /api/user/fetch-all.php to enumerate all configured users. This allows the attacker to identify accounts with elevated privileges, posing a significant risk for unauthorized access and potential exploitation of sensitive resources.
Affected Version(s)
FDS 102 2.11.0 <= 2.13.3
