A low-privileged remote attacker can enumerate all configured users and identify which accounts hold elevated privileges using the endpoint /api/user/fetch-all.php.
References
| Link | Resource |
|---|---|
| https://www.certvde.com/en/advisories/VDE-2026-078/ |
Configurations
No configuration.
History
No history.
Information
Published : 2026-08-20 09:16
Updated : 2026-09-03 16:57
NVD link : CVE-2026-14953
Mitre link : CVE-2026-14953
CVE.ORG link : CVE-2026-14953
JSON object : View
Products Affected
No product.
CWE
CWE-425
Direct Request ('Forced Browsing')
