AUGUST 24, 2026
Live Feed
Back to database
Case File

CVE-2026-35552

HIGH · CVSS 8.1 EPSS 0.28% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-07-08 · Last synced 2026-08-07

CyberRota Analysis

AI-Generated

In CAXperts UPVWebServices versions 2.4.2212.603 to 2.7.6 and UDiTH Portal versions 2026.0.0 to 2026.2.0, an authenticated remote user can exploit a lack of authorization checks to access an administrative API endpoint, enabling them to deactivate the application's license. This vulnerability poses a significant risk as it can disrupt service availability and operational integrity. Organizations using these products should prioritize remediation to prevent potential exploitation by malicious actors.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

GitHub PoC Links

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-35552
Severity
HIGH
CVSS
8.1
EPSS
0.28%

Original NVD Description

In CAXperts UPVWebServices 2.4.2212.603 through 2.7.6 and UDiTH Portal 2026.0.0 through 2026.2.0, an authenticated remote user can invoke an administrative API endpoint intended for privileged users. Due to missing authorization checks, this allows the attacker to deactivate the application's license.