← Volver al buscador de CVEs

CVE-2026-35552

UPVWebServices

Descripción

In CAXperts UPVWebServices 2.4.2212.603 through 2.7.6 and UDiTH Portal 2026.0.0 through 2026.2.0, an authenticated remote user can invoke an administrative API endpoint intended for privileged users. Due to missing authorization checks, this allows the attacker to deactivate the application-s license.

CVSS 8.1EPSS 0.27599999999999997%Riesgo 0.83
Ver fuente
Publicación
2026-07-08 22:17:13
Versiones afectadas
>=2.4.2212.603,<2.7.7
Tipo
Aplicación web
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N