SEPTEMBER 17, 2026
Live Feed
Back to database
Case File

CVE-2026-14950

CRITICAL · CVSS 9.8 EPSS 0.60%

Source: NVD + CISA KEV + EPSS · Published 2026-08-20 · Last synced 2026-09-17

CyberRota Analysis

AI-Generated

An unauthenticated remote attacker can exploit a flaw that allows them to maintain access to a session even after it should have expired, potentially leading to unauthorized access to the FDS web interface. This vulnerability significantly heightens the risk of session hijacking through stolen or shared session identifiers. Organizations utilizing affected products should prioritize patching this issue to mitigate the critical risk of unauthorized access.

CVE
CVE-2026-14950
Severity
CRITICAL
CVSS
9.8
EPSS
0.60%

Original NVD Description

An unauthenticated remote attacker in possession of a valid session identifier is able to continue using the session after it should have expired. This increases the risk associated with stolen, leaked, shared, or unattended sessions and may enable unauthorized continued access to the FDS web interface.