CVE-2026-50214

Severity CVSS v4.0:
CRITICAL
Type:
CWE-345 Insufficient Verification of Data Authenticity
Publication date:
04/06/2026
Last modified:
04/06/2026

Description

The /v1/Plan service relies entirely on a shared global API token for full administrative management, allowing arbitrary creation of zero-cost network access plans.

References to Advisories, Solutions, and Tools