SEPTEMBER 19, 2026
Live Feed
Back to database
Case File

CVE-2026-23934

MEDIUM · CVSS 5.1 EPSS 0.17%

Source: NVD + CISA KEV + EPSS · Published 2026-08-18 · Last synced 2026-09-17

CyberRota Analysis

AI-Generated

Authenticated users can exploit a vulnerability in the Frontend webserver by sending specially crafted requests to the validate.api.exists action, resulting in excessive CPU load and potential denial of service. Organizations utilizing this webserver should prioritize remediation efforts to mitigate the risk of service disruption. This issue is particularly relevant for environments where user authentication is implemented, as it could be exploited by legitimate users.

CVE
CVE-2026-23934
Severity
MEDIUM
CVSS
5.1
EPSS
0.17%

Original NVD Description

An authenticated user is able to cause disproportionate CPU load on the Frontend webserver by sending specifically crafted requests to the Frontend validate.api.exists action, leading to potential denial of service.