๐Ÿ” CVE Alert

CVE-2026-14949

MEDIUM 6.5

Frauscher Sensortechnik: FDS102 for FAdC/FAdCi R2 is vulnerable to Incorrect Authorization due to improper enforcement of role-based access control

CVSS Score
6.5
EPSS Score
0.0%
EPSS Percentile
0th

A low privileged remote attacker with a valid session can submit a request to the user creation functionality exposed through /api/user/add.php to create new accounts with arbitrary role values, including the highest privilege level used by the application.

CWE CWE-863
Vendor frauscher sensortechnik
Product fds 102
Published Aug 20, 2026
Stay Ahead of the Next One

Get instant alerts for frauscher sensortechnik fds 102

Be the first to know when new medium vulnerabilities affecting frauscher sensortechnik fds 102 are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
Attack Vector
Network
Attack Complexity
Low
Privileges Required
Low
User Interaction
None
Scope
Unchanged
Confidentiality
None
Integrity
High
Availability
None

Affected Versions

Frauscher Sensortechnik / FDS 102
2.11.0 โ‰ค 2.13.3

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
certvde.com: https://www.certvde.com/en/advisories/VDE-2026-078/