CyberRota Analysis
AI-GeneratedA low-privileged remote attacker can exploit an endpoint to enumerate all configured users and identify accounts with elevated privileges, potentially leading to unauthorized access or further attacks. Organizations with exposed APIs or user management systems should prioritize this vulnerability to mitigate the risk of account enumeration and privilege escalation. Immediate action is recommended to secure the affected endpoints and limit access.
CVE
CVE-2026-14953
Severity
MEDIUM
CVSS
4.3
EPSS
0.20%
Original NVD Description
A low-privileged remote attacker can enumerate all configured users and identify which accounts hold elevated privileges using the endpoint /api/user/fetch-all.php.