CVE-2026-23754: D-Link D-View 8 IDOR Allows Credential Disclosure and Account Takeover
D-Link D-View 8 versions 2.0.1.107 and below contain an improper access control vulnerability in backend API endpoints. Any authenticated user can supply an arbitrary userid value to retrieve sensitive credential data belonging to other users, including super administrators. The exposed credential material can be reused directly as a valid authentication secret, allowing full impersonation of the targeted account. This results in complete account takeover and full administrative control over the D-View system.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2026-23754?
CVE-2026-23754 is classified as a critical vulnerability due to its potential for credential disclosure and account takeover.
How do I fix CVE-2026-23754?
To fix CVE-2026-23754, upgrade D-Link D-View 8 to version 2.0.1.108 or later.
Who is affected by CVE-2026-23754?
CVE-2026-23754 affects any user of D-Link D-View 8 versions 2.0.1.107 and earlier.
What type of vulnerability is CVE-2026-23754?
CVE-2026-23754 is an improper access control vulnerability allowing unauthorized access to sensitive data.
What are the potential consequences of CVE-2026-23754?
The potential consequences of CVE-2026-23754 include unauthorized access to user credentials and possible account takeover.