CVE-2026-36035
Severity CVSS v4.0:
Pending analysis
Type:
CWE-284
Improper Access Control
Publication date:
14/07/2026
Last modified:
15/07/2026
Description
Incorrect access control in the /api/License/deactivateOffline endpoint of CAXPerts UniversalPlantViewer WebServices Server v2.7.6 allows authenticated attackers with low-level privileges to cause a Denial of Service (DoS) via removing the license from the webserver.
Impact
Base Score 3.x
6.50
Severity 3.x
MEDIUM



