SEPTEMBER 18, 2026
Live Feed
Back to database
Case File

CVE-2026-14953

MEDIUM · CVSS 4.3 EPSS 0.20%

Source: NVD + CISA KEV + EPSS · Published 2026-08-20 · Last synced 2026-09-18

CyberRota Analysis

AI-Generated

A low-privileged remote attacker can exploit an endpoint to enumerate all configured users and identify accounts with elevated privileges, potentially leading to unauthorized access or further attacks. Organizations with exposed APIs or user management systems should prioritize this vulnerability to mitigate the risk of account enumeration and privilege escalation. Immediate action is recommended to secure the affected endpoints and limit access.

CVE
CVE-2026-14953
Severity
MEDIUM
CVSS
4.3
EPSS
0.20%

Original NVD Description

A low-privileged remote attacker can enumerate all configured users and identify which accounts hold elevated privileges using the endpoint /api/user/fetch-all.php.