CVE-2026-14953
EUVD-2026-6322420.08.2026, 09:16
A low-privileged remote attacker can enumerate all configured users and identify which accounts hold elevated privileges using the endpoint /api/user/fetch-all.php.
Awaiting analysis
This vulnerability is currently awaiting analysis.
Common Weakness Enumeration