| ID | CVE-2026-14953 | ||||||
| Sažetak | A low-privileged remote attacker can enumerate all configured users and identify which accounts hold elevated privileges using the endpoint /api/user/fetch-all.php. | ||||||
| Reference | |||||||
| CVSS |
|
||||||
| Pristup |
|
||||||
| Impact |
|
||||||
| CVSS vektor | CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N | ||||||
| Zadnje važnije ažuriranje | 03-09-2026 - 16:57 | ||||||
| Objavljeno | 20-08-2026 - 09:16 |

