CVE-2026-14949

A low privileged remote attacker with a valid session can submit a request to the user creation functionality exposed through /api/user/add.php to create new accounts with arbitrary role values, including the highest privilege level used by the application.
Configurations

No configuration.

History

No history.

Information

Published : 2026-08-20 09:16

Updated : 2026-09-03 16:57


NVD link : CVE-2026-14949

Mitre link : CVE-2026-14949

CVE.ORG link : CVE-2026-14949


JSON object : View

Products Affected

No product.

CWE
CWE-863

Incorrect Authorization