CVE-2026-14951
Received Received - Intake

Authenticated Stored Cross-Site Request Forgery in FDS Web Interface

Vulnerability report for CVE-2026-14951, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-20

Last updated on: 2026-08-20

Assigner: CERT VDE

Description

An low privileged remote attacker can cause authenticated users to perform unintended actions in the FDS Web interface using malicious web pages.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-20
Last Modified
2026-08-20
Generated
2026-08-20
AI Q&A
2026-08-20
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Currently, no data is known.

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-352 The web application does not, or cannot, sufficiently verify whether a request was intentionally provided by the user who sent the request, which could have originated from an unauthorized actor.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability allows a low-privileged remote attacker to trick authenticated users into performing unintended actions in the FDS Web interface by using malicious web pages. The attacker exploits user interactions to trigger actions without direct access.

Detection Guidance

This vulnerability involves malicious web pages tricking authenticated users into unintended actions in the FDS Web interface. Detection requires monitoring for unusual user activity or unauthorized changes in the web interface. Check browser logs for suspicious pages and inspect network traffic for unexpected requests to the FDS Web interface.

Impact Analysis

An attacker could manipulate users into executing unauthorized actions, potentially leading to data breaches, unauthorized modifications, or system compromise. Users with legitimate access might unknowingly perform harmful operations.

Compliance Impact

This vulnerability could lead to unauthorized data access or modifications, violating GDPR's integrity and confidentiality requirements or HIPAA's safeguards for protected health information. Compliance may be compromised if sensitive data is exposed or altered.

Mitigation Strategies

Update the FDS Web interface to the latest version to patch the vulnerability. Restrict user permissions to minimize unintended actions. Monitor network traffic for suspicious web page interactions.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-14951. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart