CVE-2026-14949: Frauscher Sensortechnik: FDS102 for FAdC/FAdCi R2 is vulnerable to Incorrect Authorization due to improper enforcement of role-based access control
Published Aug 20, 2026
·Updated
A low privileged remote attacker with a valid session can submit a request to the user creation functionality exposed through /api/user/add.php to create new accounts with arbitrary role values, including the highest privilege level used by the application.
Affected Software
1 affected component
Frauscher Sensortechnik FDS102 for FAdC/FAdCi R2
Event History
Aug 20, 2026
CVE Published
via MITRE·08:19 AM
Data Sourced
via MITRE·08:19 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
Who can exploit this issue?
An attacker must be remote, have a valid authenticated session, and hold a low-privilege account. No user interaction is required.
2
What access can an attacker obtain?
The attacker can use the user-creation endpoint at /api/user/add.php to create accounts with arbitrary role values, including the application's highest privilege level. This can result in privilege escalation to the highest role.