Security Advisory

CVE-2026-14953

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2026-08-20 08:20:06
Last updated 2026-08-20 15:26:26
Assigner CERTVDE
CVSS score 5.3
State PUBLISHED

Description

A low-privileged remote attacker can enumerate all configured users and identify which accounts hold elevated privileges using the endpoint /api/user/fetch-all.php.