Unrated severityNVD Advisory· Published Jul 8, 2026· Updated Jul 9, 2026
CVE-2026-35552
CVE-2026-35552
Description
In CAXperts UPVWebServices 2.4.2212.603 through 2.7.6 and UDiTH Portal 2026.0.0 through 2026.2.0, an authenticated remote user can invoke an administrative API endpoint intended for privileged users. Due to missing authorization checks, this allows the attacker to deactivate the application's license.
Affected products
2- Range: 2.4.2212.603 - 2.7.6
- Range: 2026.0.0 - 2026.2.0
Patches
Vulnerability mechanics
References
2News mentions
0No linked articles in our index yet.