In CAXperts UPVWebServices 2.4.2212.603 through 2.7.6 and UDiTH Portal 2026.0.0 through 2026.2.0, an authenticated remote user can invoke an administrative API endpoint intended for privileged users. Due to missing authorization checks, this allows the attacker to deactivate the application's license.
References
Configurations
No configuration.
History
No history.
Information
Published : 2026-07-08 22:17
Updated : 2026-07-09 17:02
NVD link : CVE-2026-35552
Mitre link : CVE-2026-35552
CVE.ORG link : CVE-2026-35552
JSON object : View
Products Affected
No product.
CWE
CWE-862
Missing Authorization
