SEPTEMBER 19, 2026
Live Feed
Back to database
Case File

CVE-2026-14952

HIGH · CVSS 7.5 EPSS 0.50%

Source: NVD + CISA KEV + EPSS · Published 2026-08-20 · Last synced 2026-09-18

CyberRota Analysis

AI-Generated

An unauthenticated remote attacker can exploit a vulnerability in the FDS Web server to access sensitive files, including a backup archive and other critical data, via HTTP without requiring a valid session. This exposure of railway signaling and track layout information poses significant risks to operational security and safety. Organizations using the affected FDS Web server should prioritize addressing this vulnerability to prevent potential data breaches and ensure the integrity of their systems.

CVE
CVE-2026-14952
Severity
HIGH
CVSS
7.5
EPSS
0.50%

Original NVD Description

An unauthenticated remote attacker can retrieve sensible files from the FDS Web server, such as the backup archive at /FdsBackup.zip and additional files under /downloads/*, directly over HTTP without a valid session. These files disclose detailed railway signaling and track layout information that should not be available to unauthenticated users.