CVE-2026-14953: Frauscher Sensortechnik: FDS102 for FAdC/FAdCi R2 is Missing Authorization due to improper enforcement of role-based access control
Published Aug 20, 2026
·Updated
A low-privileged remote attacker can enumerate all configured users and identify which accounts hold elevated privileges using the endpoint /api/user/fetch-all.php.
Affected Software
1 affected component
Frauscher Sensortechnik FDS102 for FAdC/FAdCi R2
Event History
Aug 20, 2026
CVE Published
via MITRE·08:20 AM
Data Sourced
via MITRE·08:20 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What access does an attacker need to exploit this issue?
The attacker needs remote access to the affected system and a low-privileged account. No user interaction is required.
2
What information can be exposed?
A low-privileged attacker can enumerate all configured users and determine which accounts have elevated privileges through the /api/user/fetch-all.php endpoint.