SEPTEMBER 18, 2026
Live Feed
Back to database
Case File

CVE-2026-14949

MEDIUM · CVSS 6.5 EPSS 0.26%

Source: NVD + CISA KEV + EPSS · Published 2026-08-20 · Last synced 2026-09-18

CyberRota Analysis

AI-Generated

A low-privileged remote attacker with a valid session can exploit a vulnerability in the user creation functionality of the affected application to create new accounts with arbitrary roles, potentially granting themselves the highest privileges. This could lead to unauthorized access and control over sensitive data and functionalities. Organizations using this application should prioritize patching this vulnerability to mitigate the risk of privilege escalation and unauthorized account creation.

CVE
CVE-2026-14949
Severity
MEDIUM
CVSS
6.5
EPSS
0.26%

Original NVD Description

A low privileged remote attacker with a valid session can submit a request to the user creation functionality exposed through /api/user/add.php to create new accounts with arbitrary role values, including the highest privilege level used by the application.