CVE-2026-14952

An unauthenticated remote attacker can retrieve sensible files from the FDS Web server, such as the backup archive at /FdsBackup.zip and additional files under /downloads/*, directly over HTTP without a valid session. These files disclose detailed railway signaling and track layout information that should not be available to unauthenticated users.
Configurations

No configuration.

History

No history.

Information

Published : 2026-08-20 09:16

Updated : 2026-09-03 16:57


NVD link : CVE-2026-14952

Mitre link : CVE-2026-14952

CVE.ORG link : CVE-2026-14952


JSON object : View

Products Affected

No product.

CWE
CWE-306

Missing Authentication for Critical Function