CVE-2026-14949
Severity CVSS v4.0:
HIGH
Type:
Unavailable / Other
Publication date:
20/08/2026
Last modified:
20/08/2026
Description
A low privileged remote attacker with a valid session can submit a request to the user creation functionality exposed through /api/user/add.php to create new accounts with arbitrary role values, including the highest privilege level used by the application.
Impact
Base Score 4.0
8.50
Severity 4.0
HIGH
Base Score 3.x
6.50
Severity 3.x
MEDIUM


