CVE-2026-35552

In CAXperts UPVWebServices 2.4.2212.603 through 2.7.6 and UDiTH Portal 2026.0.0 through 2026.2.0, an authenticated remote user can invoke an administrative API endpoint intended for privileged users. Due to missing authorization checks, this allows the attacker to deactivate the application's license.
Configurations

No configuration.

History

No history.

Information

Published : 2026-07-08 22:17

Updated : 2026-07-09 17:02


NVD link : CVE-2026-35552

Mitre link : CVE-2026-35552

CVE.ORG link : CVE-2026-35552


JSON object : View

Products Affected

No product.

CWE
CWE-862

Missing Authorization