CyberRota Analysis
AI-GeneratedIn CAXperts UPVWebServices versions 2.4.2212.603 to 2.7.6 and UDiTH Portal versions 2026.0.0 to 2026.2.0, an authenticated remote user can exploit a lack of authorization checks to access an administrative API endpoint, enabling them to deactivate the application's license. This vulnerability poses a significant risk as it can disrupt service availability and operational integrity. Organizations using these products should prioritize remediation to prevent potential exploitation by malicious actors.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
In CAXperts UPVWebServices 2.4.2212.603 through 2.7.6 and UDiTH Portal 2026.0.0 through 2026.2.0, an authenticated remote user can invoke an administrative API endpoint intended for privileged users. Due to missing authorization checks, this allows the attacker to deactivate the application's license.